Jump to content

Build Theme!
  •  
  • Infected?

WE'RE SURE THAT YOU'LL LOVE US!

Hey there! :wub: Looks like you're enjoying the discussion, but you're not signed up for an account. When you create an account, we remember exactly what you've read, so you always come right back where you left off. You also get notifications, here and via email, whenever new posts are made. You can like posts to share the love. :D Join 93085 other members! Anybody can ask, anybody can answer. Consistently helpful members may be invited to become staff. Here's how it works. Virus cleanup? Start here -> Malware Removal Forum.

Try What the Tech -- It's free!


Photo

Malwarebytes shows 2 Hijack.windowsupdates which cannot be removed


  • Please log in to reply
32 replies to this topic

#1 Shalgi

Shalgi

    New Member

  • Authentic Member
  • Pip
  • 17 posts

Posted 18 January 2014 - 08:51 AM

Hi,

 

I've ran Malwarebytes Anti-Malware (updated to today) in safemode and regular mode and it showed that I have 2 Hijack.windowsupdates that cannot be removed. 

MBAM tries to remove them and asks me to reboot, but running again after reboot gives the same result.

 

I'd appreciate any assistance.

Thank you very much,

Aviv

 

------------------------------------------------------------------------------------------

 

Here's the log of MBAM:

 

Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org
 
Database version: v2014.01.17.09
 
Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Aviv Shalgi :: AVIV [administrator]
 
18/01/2014 13:07:46
mbam-log-2014-01-18 (13-07-46).txt
 
Scan type: Full scan (C:\|D:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 626977
Time elapsed: 2 hour(s), 42 minute(s), 22 second(s)
 
Memory Processes Detected: 0
(No malicious items detected)
 
Memory Modules Detected: 0
(No malicious items detected)
 
Registry Keys Detected: 0
(No malicious items detected)
 
Registry Values Detected: 0
(No malicious items detected)
 
Registry Data Items Detected: 2
HKLM\System\CurrentControlSet\Services\BITS|ImagePath (Hijack.WindowsUpdates) -> Bad: (%fystemRoot%\system32\svchost.exe -k netsvcs) Good: (%SystemRoot%\System32\svchost.exe -k netsvcs) -> Delete on reboot.
HKLM\System\CurrentControlSet\Services\wuauserv|ImagePath (Hijack.WindowsUpdates) -> Bad: (%fystemroot%\system32\svchost.exe -k netsvcs) Good: (%SystemRoot%\System32\svchost.exe -k netsvcs) -> Delete on reboot.
 
Folders Detected: 0
(No malicious items detected)
 
Files Detected: 0
(No malicious items detected)
 
(end)
 

-------------------------------------------------------------------------------------------------
 
 

I've downloaded OTL as instructed in the pinned message, so here are the results.

 

OTL.txt:

OTL logfile created on: 18/01/2014 16:32:45 - Run 1
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Documents and Settings\Aviv Shalgi\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 0000040D | Country: Israel | Language: HEB | Date Format: dd/MM/yyyy
 
2.00 Gb Total Physical Memory | 0.36 Gb Available Physical Memory | 17.90% Memory free
3.85 Gb Paging File | 2.15 Gb Available in Paging File | 56.02% Paging File free
Paging file location(s): c:\pagefile.sys 2046 4092 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 48.83 Gb Total Space | 13.38 Gb Free Space | 27.40% Space Free | Partition Type: NTFS
Drive D: | 416.93 Gb Total Space | 72.42 Gb Free Space | 17.37% Space Free | Partition Type: NTFS
 
Computer Name: AVIV | User Name: Aviv Shalgi | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\Documents and Settings\Aviv Shalgi\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Documents and Settings\Aviv Shalgi\Local Settings\Application Data\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - c:\Program Files\McAfee\SiteAdvisor\saUI.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe (McAfee, Inc.)
PRC - C:\Documents and Settings\Aviv Shalgi\Application Data\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
PRC - C:\Program Files\Java\jre7\bin\jqs.exe (Oracle Corporation)
PRC - C:\Program Files\LogMeIn\x86\ramaint.exe (LogMeIn, Inc.)
PRC - C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe (LogMeIn, Inc.)
PRC - C:\Documents and Settings\Aviv Shalgi\Local Settings\Application Data\Google\Update\1.3.22.3\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Program Files\McAfee\MSC\McAPExe.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe (McAfee, Inc.)
PRC - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\WINDOWS\system32\mfevtps.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe (McAfee, Inc.)
PRC - C:\Documents and Settings\Aviv Shalgi\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe (Google)
PRC - C:\Program Files\Common Files\McAfee\Platform\McUICnt.exe (McAfee, Inc.)
PRC - C:\Program Files\real\realplayer\Update\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe ()
PRC - C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Flexera Software, Inc.)
PRC - C:\Documents and Settings\All Users\Application Data\Skype\Toolbars\Skype C2C Service\c2c_service.exe (Skype Technologies S.A.)
PRC - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\acrotray.exe (Adobe Systems Inc.)
PRC - C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE (Microsoft Corporation)
PRC - C:\Program Files\LogMeIn\x86\LogMeIn.exe (LogMeIn, Inc.)
PRC - C:\Program Files\LogMeIn\x86\LogMeInSystray.exe (LogMeIn, Inc.)
PRC - C:\Program Files\ASUS\Six Engine\SixEngine.exe ()
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft LifeCam\MSCamS32.exe (Microsoft Corporation)
PRC - C:\WINDOWS\vVX1000.exe (Microsoft Corporation)
 
 
========== Modules (No Company Name) ==========
 
MOD - C:\Documents and Settings\Aviv Shalgi\Local Settings\Application Data\Google\Chrome\User Data\SwiftShader\1.0.5.0\libGLESv2.dll ()
MOD - C:\Documents and Settings\Aviv Shalgi\Local Settings\Application Data\Google\Chrome\User Data\SwiftShader\1.0.5.0\libEGL.dll ()
MOD - C:\Documents and Settings\Aviv Shalgi\Local Settings\Application Data\Google\Chrome\Application\32.0.1700.76\ppgooglenaclpluginchrome.dll ()
MOD - C:\Documents and Settings\Aviv Shalgi\Local Settings\Application Data\Google\Chrome\Application\32.0.1700.76\PepperFlash\pepflashplayer.dll ()
MOD - C:\Documents and Settings\Aviv Shalgi\Local Settings\Application Data\Google\Chrome\Application\32.0.1700.76\pdf.dll ()
MOD - C:\Documents and Settings\Aviv Shalgi\Local Settings\Application Data\Google\Chrome\Application\32.0.1700.76\ffmpegsumo.dll ()
MOD - C:\Documents and Settings\Aviv Shalgi\Application Data\Dropbox\bin\wxmsw28uh_vc.dll ()
MOD - C:\Program Files\DivX\DivX Update\DivXUpdateCheck.dll ()
MOD - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
MOD - C:\Documents and Settings\Aviv Shalgi\Application Data\Dropbox\bin\libcef.dll ()
MOD - C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF ()
MOD - c:\Program Files\McAfee\SiteAdvisor\mcfrmwk.dll ()
MOD - c:\Program Files\McAfee\SiteAdvisor\cntscan.dll ()
MOD - c:\Program Files\McAfee\SiteAdvisor\apengine.dll ()
MOD - C:\Program Files\ASUS\Six Engine\SixEngine.exe ()
MOD - C:\Program Files\ASUS\Six Engine\AsSpindownTimeout.dll ()
MOD - C:\WINDOWS\system32\msdmo.dll ()
MOD - C:\WINDOWS\system32\devenum.dll ()
MOD - C:\Program Files\WinRAR\RarExt.dll ()
MOD - C:\WINDOWS\system32\AsIO.dll ()
MOD - C:\Program Files\ASUS\Six Engine\pngio.dll ()
 
 
========== Services (SafeList) ==========
 
SRV - (NMSAccess) -- C:\Program Files\Blaze Media Pro\NMSAccess32.exe File not found
SRV - (HidServ) -- %SystemRoot%\System32\hidserv.dll File not found
SRV - (McAfee SiteAdvisor Service) -- C:\Program Files\McAfee\SiteAdvisor\McSACore.exe (McAfee, Inc.)
SRV - (JavaQuickStarterService) -- C:\Program Files\Java\jre7\bin\jqs.exe (Oracle Corporation)
SRV - (LMIMaint) -- C:\Program Files\LogMeIn\x86\ramaint.exe (LogMeIn, Inc.)
SRV - (LMIGuardianSvc) -- C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe (LogMeIn, Inc.)
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (McAPExe) -- C:\Program Files\McAfee\MSC\McAPExe.exe (McAfee, Inc.)
SRV - (mfecore) -- C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe (McAfee, Inc.)
SRV - (mfevtp) -- C:\WINDOWS\system32\mfevtps.exe (McAfee, Inc.)
SRV - (mfefire) -- C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe ()
SRV - (RealNetworks Downloader Resolver Service) -- C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe ()
SRV - (McODS) -- C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SRV - (McProxy) -- C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (mcpltsvc) -- C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McNaiAnn) -- C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McMPFSvc) -- C:\Program Files\Common Files\Mcafee\Platform\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (mcbootdelaystartsvc) -- C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (HomeNetSvc) -- C:\Program Files\Common Files\Mcafee\Platform\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (FLEXnet Licensing Service) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Flexera Software, Inc.)
SRV - (Skype C2C Service) -- C:\Documents and Settings\All Users\Application Data\Skype\Toolbars\Skype C2C Service\c2c_service.exe (Skype Technologies S.A.)
SRV - (SkypeUpdate) -- C:\Program Files\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (LogMeIn) -- C:\Program Files\LogMeIn\x86\LogMeIn.exe (LogMeIn, Inc.)
SRV - (Microsoft SharePoint Workspace Audit Service) -- C:\Program Files\Microsoft Office\Office14\GROOVE.EXE (Microsoft Corporation)
SRV - (SandraAgentSrv) -- C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2009.SP2\RpcAgentSrv.exe (SiSoftware)
SRV - (AVGEMS) -- C:\Program Files\Grisoft\AVG Free\avgemc.exe (GRISOFT, s.r.o.)
SRV - (Avg7UpdSvc) -- C:\Program Files\Grisoft\AVG Free\avgupsvc.exe (GRISOFT, s.r.o.)
SRV - (Avg7Alrt) -- C:\Program Files\Grisoft\AVG Free\avgamsvr.exe (GRISOFT, s.r.o.)
SRV - (MSCamSvc) -- C:\Program Files\Microsoft LifeCam\MSCamS32.exe (Microsoft Corporation)
SRV - (msvsmon80) -- C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe (Microsoft Corporation)
 
 
========== Driver Services (SafeList) ==========
 
DRV - (WDICA) --  File not found
DRV - (PDRFRAME) --  File not found
DRV - (PDRELI) --  File not found
DRV - (PDFRAME) --  File not found
DRV - (PDCOMP) --  File not found
DRV - (PCIDump) --  File not found
DRV - (lbrtfdc) --  File not found
DRV - (Lbd) -- system32\DRIVERS\Lbd.sys File not found
DRV - (Lavasoft Kernexplorer) -- C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys File not found
DRV - (i2omgmt) --  File not found
DRV - (Changer) --  File not found
DRV - (bf629657) -- C:\WINDOWS\System32\drivers\bf629657.sys File not found
DRV - (AvgTdi) -- C:\WINDOWS\System32\Drivers\avgtdi.sys File not found
DRV - (a06v664u) --  File not found
DRV - (LMIRfsClientNP) -- C:\WINDOWS\System32\LMIRfsClientNP.dll (LogMeIn, Inc.)
DRV - (mfencrk) -- C:\WINDOWS\system32\drivers\mfencrk.sys (McAfee, Inc.)
DRV - (mfencbdc) -- C:\WINDOWS\system32\drivers\mfencbdc.sys (McAfee, Inc.)
DRV - (cfwids) -- C:\WINDOWS\system32\drivers\cfwids.sys (McAfee, Inc.)
DRV - (mfetdi2k) -- C:\WINDOWS\system32\drivers\mfetdi2k.sys (McAfee, Inc.)
DRV - (mfehidk) -- C:\WINDOWS\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mfendiskmp) -- C:\WINDOWS\system32\drivers\mfendisk.sys (McAfee, Inc.)
DRV - (mfendisk) -- C:\WINDOWS\system32\drivers\mfendisk.sys (McAfee, Inc.)
DRV - (mfefirek) -- C:\WINDOWS\system32\drivers\mfefirek.sys (McAfee, Inc.)
DRV - (mfebopk) -- C:\WINDOWS\system32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (mfeavfk) -- C:\WINDOWS\system32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfeapfk) -- C:\WINDOWS\system32\drivers\mfeapfk.sys (McAfee, Inc.)
DRV - (HipShieldK) -- C:\WINDOWS\system32\drivers\HipShieldK.sys (McAfee, Inc.)
DRV - (sptd) -- C:\WINDOWS\system32\drivers\sptd.sys (Duplex Secure Ltd.)
DRV - (Netaapl) -- C:\WINDOWS\system32\drivers\netaapl.sys (Apple Inc.)
DRV - (LMIRfsDriver) -- C:\WINDOWS\system32\drivers\LMIRfsDriver.sys (LogMeIn, Inc.)
DRV - (LMIInfo) -- C:\Program Files\LogMeIn\x86\rainfo.sys (LogMeIn, Inc.)
DRV - (SANDRA) -- C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2009.SP2\WNt500x86\sandra.sys (SiSoftware)
DRV - (RT73) -- C:\WINDOWS\system32\drivers\rt73.sys (Ralink Technology, Corp.)
DRV - (AvgClean) -- C:\WINDOWS\system32\drivers\avgclean.sys (GRISOFT, s.r.o.)
DRV - (Avg7RsXP) -- C:\WINDOWS\system32\drivers\avg7rsxp.sys (GRISOFT, s.r.o.)
DRV - (Avg7RsW) -- C:\WINDOWS\system32\drivers\avg7rsw.sys (GRISOFT, s.r.o.)
DRV - (Avg7Core) -- C:\WINDOWS\system32\drivers\avg7core.sys (GRISOFT, s.r.o.)
DRV - (RsFx0102) -- C:\WINDOWS\system32\drivers\RsFx0102.sys (Microsoft Corporation)
DRV - (mv61xx) -- C:\WINDOWS\system32\drivers\mv61xx.sys (Marvell Semiconductor, Inc.)
DRV - (IntcAzAudAddService) -- C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (L1e) -- C:\WINDOWS\system32\drivers\l1e51x86.sys (Atheros Communications, Inc.)
DRV - (AsIO) -- C:\WINDOWS\system32\drivers\AsIO.sys ()
DRV - (VX1000) -- C:\WINDOWS\system32\drivers\VX1000.sys (Microsoft Corporation)
DRV - (MTsensor) -- C:\WINDOWS\system32\drivers\ASACPI.sys ()
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.c...ferrer:source?}
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,AlwaysUseDefaultPrinter = yes
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://blekko.com/ws...39&tbp=homepage
IE - HKCU\..\URLSearchHook:  - No CLSID value found
IE - HKCU\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKCU\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.c...Box&Form=IE8SRC
IE - HKCU\..\SearchScopes\{248F65C0-A7F9-4E9D-8C63-90C01A27C079}: "URL" = http://search.yahoo....p={SearchTerms}
IE - HKCU\..\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}: "URL" = http://blekko.com/ws...q={searchTerms}
IE - HKCU\..\SearchScopes\{6552c7dd-90a4-4387-b795-f8f96747de19}: "URL" = http://www.icq.com/s...erms}&ch_id=osd
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...urceid=ie7&rlz=
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.condui...&ctid=CT3072253
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
 
========== FireFox ==========
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: D:\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Web Player Plug-In,version=1.0.0: C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.51.2: C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.51.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL ()
FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.3: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pack.google.com/Google Updater;version=14: C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google)
FF - HKLM\Software\MozillaPlugins\@parallelgraphics.com/Cortona: C:\Program Files\Common Files\ParallelGraphics\Cortona\npCortona.dll (ParallelGraphics)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=16.0.3.51: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlchromebrowserrecordext;version=1.3.3: C:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlhtml5videoshim;version=1.3.3: C:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlpepperflashvideoshim;version=1.3.3: C:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=16.0.3.51: c:\program files\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@realnetworks.com/npdlplugin;version=1: C:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@citrixonline.com/appdetectorplugin: C:\Documents and Settings\Aviv Shalgi\Local Settings\Application Data\Citrix\Plugins\104\npappdetector.dll (Citrix Online)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Documents and Settings\Aviv Shalgi\Application Data\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O1DPlugin: C:\Documents and Settings\Aviv Shalgi\Application Data\Mozilla\plugins\npo1d.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Documents and Settings\Aviv Shalgi\Application Data\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Aviv Shalgi\Local Settings\Application Data\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Aviv Shalgi\Local Settings\Application Data\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Documents and Settings\Aviv Shalgi\Local Settings\Application Data\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files\McAfee\SiteAdvisor [2014/01/10 11:58:28 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{97E22097-9A2F-45b1-8DAF-36AD648C7EF4}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013/09/07 12:52:01 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{DF153AFF-6948-45d7-AC98-4FC4AF8A08E2}: C:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ [2013/09/07 12:52:01 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\thunderbird\extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird
 
[2012/06/17 22:57:51 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Aviv Shalgi\Application Data\Mozilla\Firefox\extensions
[2012/06/17 22:57:53 | 000,000,000 | ---D | M] (uTorrentControl2 Community Toolbar) -- C:\Documents and Settings\Aviv Shalgi\Application Data\Mozilla\Firefox\extensions\{687578b9-7132-4a7a-80e4-30ee31099e03}
 
========== Chrome  ==========
 
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:bookmarkBarPinned}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&xssi=t&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}{google:pageClassification}sugkey={google:suggestAPIKeyParameter},
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Aviv Shalgi\Local Settings\Application Data\Google\Chrome\Application\32.0.1700.76\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Disabled) = C:\Documents and Settings\Aviv Shalgi\Local Settings\Application Data\Google\Chrome\Application\32.0.1700.76\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Aviv Shalgi\Local Settings\Application Data\Google\Chrome\Application\32.0.1700.76\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Aviv Shalgi\Local Settings\Application Data\Google\Chrome\User Data\PepperFlash\11.2.31.144\pepflashplayer.dll
CHR - plugin: Google Talk Plugin (Enabled) = C:\Documents and Settings\Aviv Shalgi\Application Data\Mozilla\plugins\npgoogletalk.dll
CHR - plugin: Google Talk Plugin Video Accelerator (Enabled) = C:\Documents and Settings\Aviv Shalgi\Application Data\Mozilla\plugins\npgtpo3dautoplugin.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Disabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Disabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Disabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Disabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Disabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Disabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Disabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: RealNetworks™ Chrome Background Extension Plug-In (32-bit)  (Enabled) = C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
CHR - plugin: RealPlayer™ HTML5VideoShim Plug-In (32-bit)  (Enabled) = C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
CHR - plugin: RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit)  (Enabled) = c:\program files\real\realplayer\Netscape6\nppl3260.dll
CHR - plugin: RealPlayer Download Plugin (Enabled) = c:\program files\real\realplayer\Netscape6\nprpplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Aviv Shalgi\Local Settings\Application Data\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Google Updater (Enabled) = C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll
CHR - plugin: Unity Player (Enabled) = C:\Documents and Settings\Aviv Shalgi\Local Settings\Application Data\Unity\WebPlayer\loader\npUnity3D32.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files\Microsoft\Office Live\npOLW.dll
CHR - plugin: Cortona3D Viewer (Enabled) = C:\Program Files\Common Files\ParallelGraphics\Cortona\npCortona.dll
CHR - plugin: DivX VOD Helper Plug-in (Enabled) = C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll
CHR - plugin: DivX Plus Web Player (Enabled) = C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Java™ Platform SE 6 U31 (Enabled) = C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\WINDOWS\system32\Adobe\Director\np32dsw.dll
CHR - plugin: iTunes Application Detector (Enabled) = D:\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = c:\program files\real\realplayer\Netscape6\nprjplug.dll
CHR - plugin: McAfee SecurityCenter (Enabled) = c:\progra~1\mcafee\msc\npmcsn~1.dll
CHR - Extension: YouTube = C:\Documents and Settings\Aviv Shalgi\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: \u05D7\u05D9\u05E4\u05D5\u05E9 Google = C:\Documents and Settings\Aviv Shalgi\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: SiteAdvisor = C:\Documents and Settings\Aviv Shalgi\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.6.4.1311_0\
CHR - Extension: AdBlock = C:\Documents and Settings\Aviv Shalgi\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.6.18_0\
CHR - Extension: RealDownloader = C:\Documents and Settings\Aviv Shalgi\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji\1.3.3_0\
CHR - Extension: Any.do Extension = C:\Documents and Settings\Aviv Shalgi\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\kdadialhpiikehpdeejjeiikopddkjem\1.0.3.8_0\
CHR - Extension: Any.do Extension = C:\Documents and Settings\Aviv Shalgi\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\kdadialhpiikehpdeejjeiikopddkjem\1.0.3.8_0\.orig
CHR - Extension: Skype Click to Call = C:\Documents and Settings\Aviv Shalgi\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\6.4.0.11328_0\
CHR - Extension: Google Wallet = C:\Documents and Settings\Aviv Shalgi\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_1\
CHR - Extension: Gmail = C:\Documents and Settings\Aviv Shalgi\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\
CHR - Extension: RSS Feed Reader = C:\Documents and Settings\Aviv Shalgi\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pnjaodmkngahhkoihejjehlcdlnohgmp\5.2.2_0\
 
O1 HOSTS File: ([2009/02/22 19:43:07 | 000,000,770 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1       localhost
O2 - BHO: (RealNetworks Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
O2 - BHO: (no name) - {54B02808-B60E-44CD-A72D-9865117E4E62} - No CLSID value found.
O2 - BHO: (AGFormHelperObj Class) - {6620E618-1AB9-4EB2-ACA4-CBBE9066DBE6} - C:\Program Files\agat\AGForm\AGFormsHelper.dll (Agat)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll (Google Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (AGForms) - {ed2e7de7-07db-4941-a06d-f780b93ba730} - C:\Program Files\agat\AGForm\AGForms.dll (Agat)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: []  File not found
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [BCSSync] C:\Program Files\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation)
O4 - HKLM..\Run: [DivXMediaServer] C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe (DivX, LLC)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [LifeCam] C:\Program Files\Microsoft LifeCam\LifeExp.exe (Microsoft Corporation)
O4 - HKLM..\Run: [LogMeIn GUI] C:\Program Files\LogMeIn\x86\LogMeInSystray.exe (LogMeIn, Inc.)
O4 - HKLM..\Run: [mcpltui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [Six Engine] C:\Program Files\ASUS\Six Engine\SixEngine.exe ()
O4 - HKLM..\Run: [TkBellExe] C:\program files\real\realplayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [VX1000] C:\WINDOWS\vVX1000.exe (Microsoft Corporation)
O4 - HKCU..\Run: [OfficeSyncProcess] C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE (Microsoft Corporation)
O4 - HKCU..\Run: [Uniblue RegistryBooster 2009] C:\Program Files\Uniblue\RegistryBooster\RegistryBooster.exe /S File not found
O4 - Startup: C:\Documents and Settings\Aviv Shalgi\Start Menu\Programs\Startup\Dropbox.lnk = C:\Documents and Settings\Aviv Shalgi\Application Data\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &ייצוא אל Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: &יצא ל- Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Append to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: ש&לח אל OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: שלח אל OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : ש&לח אל OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: ה&ערות מקושרות של OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : ה&ערות מקושרות של OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: ICQ6 - {e59eb121-f339-4851-a3ba-fe49c35617c2} - C:\ICQ\ICQ6.5\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ6 - {e59eb121-f339-4851-a3ba-fe49c35617c2} - C:\ICQ\ICQ6.5\ICQ.exe (ICQ, LLC.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: cipcam.com ([e3405] http in Trusted sites)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebo...toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macr...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.micr...heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} http://www.nvidia.co.../sysreqlab3.cab (System Requirements Lab Class)
O16 - DPF: {20a60f0d-9afa-4515-a0fd-83bd84642501} http://messenger.zon...kr.cab56986.cab (Checkers Class)
O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} https://icitrix.tau....ca32/wficac.cab (Citrix ICA Client)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset...lineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebo...oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.ma...r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {A4150320-98EC-4DB6-9BFB-EBF4B6FBEB16} http://98.216.50.69:.../DVM_IPCam2.ocx (DVM_IPCam2 Control)
O16 - DPF: {c3f79a2b-b9b4-4a66-b012-3ee46475b072} http://messenger.zon...nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {e2883e8f-472f-4fb0-9522-ac9bf37916a7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {f5a7706b-b9c0-4c89-a715-7a0c6b05dd48} http://messenger.zon...er.cab56986.cab (Minesweeper Flags Class)
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} https://secure.logme...trl.cab?lmi=100 (Performance Viewer Activex Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 80.179.52.100 80.179.55.100
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{27F44B34-5C4A-4752-8611-55885738EBB3}: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{66A3517E-5729-4EE2-8E7F-0378696C8B04}: DhcpNameServer = 80.179.52.100 80.179.55.100
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{93ACEF3B-9BE9-4D31-AD24-A3FE2EB048AF}: DhcpNameServer = 10.0.0.138
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\OrCAD\OrCAD_10.3\tools\capture\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\OrCAD\OrCAD_10.3\tools\capture\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl.dll (McAfee, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\LMIinit: DllName - (LMIinit.dll) - C:\WINDOWS\System32\LMIinit.dll (LogMeIn, Inc.)
O22 - SharedTaskScheduler: {1984DD45-52CF-49cd-AB77-18F378FEA264} - FencesShellExt - C:\Program Files\Stardock\Fences\FencesMenu.dll (Stardock)
O24 - Desktop WallPaper: C:\WINDOWS\SOH.BMP
O24 - Desktop BackupWallPaper: C:\WINDOWS\SOH.BMP
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{593a0c3a-aba4-11de-ba90-00221546d103}\Shell\AutoRun\command - "" = F:\setup.exe
O33 - MountPoints2\{62c72e17-57a6-11df-bba5-00221546d103}\Shell - "" = AutoRun
O33 - MountPoints2\{62c72e17-57a6-11df-bba5-00221546d103}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{62c72e17-57a6-11df-bba5-00221546d103}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -a
O33 - MountPoints2\{70155380-079d-11e1-be27-00221546d103}\Shell - "" = AutoRun
O33 - MountPoints2\{70155380-079d-11e1-be27-00221546d103}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{70155380-079d-11e1-be27-00221546d103}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -a
O33 - MountPoints2\{c99e4c04-c408-11df-bc44-00221546d103}\Shell\AutoRun\command - "" = I:\DVAP.exe
O33 - MountPoints2\{db9fb7a8-1759-11e1-be42-00221546d103}\Shell - "" = AutoRun
O33 - MountPoints2\{db9fb7a8-1759-11e1-be42-00221546d103}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{db9fb7a8-1759-11e1-be42-00221546d103}\Shell\AutoRun\command - "" = F:\DPFMate.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
 
NetSvcs: 6to4 -  File not found
NetSvcs: HidServ - %SystemRoot%\System32\hidserv.dll File not found
NetSvcs: Ias -  File not found
NetSvcs: Iprip -  File not found
NetSvcs: Irmon -  File not found
NetSvcs: NWCWorkstation -  File not found
NetSvcs: Nwsapagent -  File not found
NetSvcs: WmdmPmSp -  File not found
 
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.XVID - C:\WINDOWS\System32\xvidvfw.dll ()
Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
========== Files/Folders - Created Within 30 Days ==========
 
[2014/01/18 16:27:43 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Aviv Shalgi\Desktop\OTL.exe
[2014/01/17 14:51:55 | 000,264,616 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\javaws.exe
[2014/01/17 14:51:55 | 000,145,408 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\javacpl.cpl
[2014/01/17 14:51:44 | 000,175,016 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\javaw.exe
[2014/01/17 14:51:44 | 000,174,504 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\java.exe
[2014/01/17 14:51:44 | 000,094,632 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\WindowsAccessBridge.dll
[2014/01/17 14:51:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Java
[2014/01/16 19:54:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Aviv Shalgi\Desktop\Taptica
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[3 C:\Documents and Settings\All Users\Application Data\*.tmp files -> C:\Documents and Settings\All Users\Application Data\*.tmp -> ]
[19 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2014/01/18 16:27:44 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Aviv Shalgi\Desktop\OTL.exe
[2014/01/18 15:59:35 | 000,000,290 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-789336058-602609370-839522115-1003.job
[2014/01/18 15:59:33 | 000,000,290 | ---- | M] () -- C:\WINDOWS\tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-789336058-602609370-839522115-1003.job
[2014/01/18 15:59:32 | 000,000,298 | ---- | M] () -- C:\WINDOWS\tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-789336058-602609370-839522115-1003.job
[2014/01/18 15:59:31 | 000,001,665 | ---- | M] () -- C:\Documents and Settings\Aviv Shalgi\Start Menu\Programs\Startup\Monitor Ink Alerts - HP Deskjet 2510 series.lnk
[2014/01/18 15:58:53 | 000,208,485 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2014/01/18 15:58:00 | 000,001,032 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-789336058-602609370-839522115-1003UA.job
[2014/01/18 15:57:36 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2014/01/18 15:57:32 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2014/01/18 15:52:00 | 000,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2014/01/18 15:46:04 | 000,000,830 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2014/01/18 14:00:00 | 000,000,868 | ---- | M] () -- C:\WINDOWS\tasks\Google Software Updater.job
[2014/01/18 12:59:00 | 000,000,486 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2014/01/18 12:35:20 | 000,000,434 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{9ADC7FC0-9B82-41FE-8119-8BAC2B8B17DF}.job
[2014/01/17 18:58:00 | 000,000,980 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-789336058-602609370-839522115-1003Core.job
[2014/01/17 13:04:24 | 000,002,342 | ---- | M] () -- C:\Documents and Settings\Aviv Shalgi\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2014/01/17 13:04:24 | 000,002,324 | ---- | M] () -- C:\Documents and Settings\Aviv Shalgi\Desktop\Google Chrome.lnk
[2014/01/16 10:27:48 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2014/01/13 18:02:08 | 000,000,298 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-789336058-602609370-839522115-1003.job
[2014/01/09 19:58:23 | 000,001,046 | ---- | M] () -- C:\Documents and Settings\Aviv Shalgi\Start Menu\Programs\Startup\Dropbox.lnk
[2014/01/08 15:13:09 | 000,185,856 | ---- | M] () -- C:\Documents and Settings\Aviv Shalgi\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/12/22 20:21:23 | 000,418,248 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[3 C:\Documents and Settings\All Users\Application Data\*.tmp files -> C:\Documents and Settings\All Users\Application Data\*.tmp -> ]
[19 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2014/01/09 19:58:23 | 000,001,046 | ---- | C] () -- C:\Documents and Settings\Aviv Shalgi\Start Menu\Programs\Startup\Dropbox.lnk
[2013/02/01 18:10:28 | 000,000,057 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\Ament.ini
[2011/11/17 22:17:47 | 000,000,600 | ---- | C] () -- C:\Documents and Settings\Aviv Shalgi\Application Data\winscp.rnd
[2011/07/13 19:43:00 | 000,060,304 | ---- | C] () -- C:\Documents and Settings\Aviv Shalgi\g2mdlhlpx.exe
[2009/02/22 16:52:50 | 008,507,392 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\sandra.mda
[2009/01/03 20:28:45 | 000,011,430 | ---- | C] () -- C:\Documents and Settings\Aviv Shalgi\gsview32.ini
[2008/12/16 16:58:16 | 000,000,664 | ---- | C] () -- C:\Documents and Settings\Aviv Shalgi\Local Settings\Application Data\d3d9caps.dat
[2008/10/28 13:26:25 | 000,185,856 | ---- | C] () -- C:\Documents and Settings\Aviv Shalgi\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
 
========== ZeroAccess Check ==========
 
[2008/11/03 16:48:26 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll -- [2008/04/14 02:12:05 | 001,499,136 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll -- [2009/02/09 14:10:48 | 000,473,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll -- [2008/04/14 02:12:08 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
========== LOP Check ==========
 
[2013/10/21 21:07:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\188F1432-103A-4ffb-80F1-36B633C5C9E1
[2009/10/10 13:30:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\avg7
[2012/12/07 21:28:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\blekko toolbars
[2012/09/08 19:05:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
[2013/06/29 19:23:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DassaultSystemes
[2011/08/28 16:06:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Easybits GO
[2008/09/12 19:46:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ESET
[2009/05/07 13:42:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FreeRIP
[2008/09/12 20:04:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Grisoft
[2009/09/04 17:44:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ICQ
[2012/09/08 15:31:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\LockLizard
[2014/01/18 01:09:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\LogMeIn
[2008/09/12 20:33:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\OrbNetworks
[2009/04/06 13:06:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PopCap
[2008/09/12 17:09:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2010/04/17 20:23:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/09/11 14:40:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/05/14 14:01:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2013/10/14 21:54:58 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{A87EB928-0C6C-4071-AEF1-59E32BAEDF1B}
[2012/07/23 20:15:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Aviv Shalgi\Application Data\Ad-Aware Antivirus
[2008/09/15 11:08:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Aviv Shalgi\Application Data\AVG7
[2012/02/12 16:28:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Aviv Shalgi\Application Data\BitTorrent
[2012/09/08 18:58:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Aviv Shalgi\Application Data\blekkotb_019
[2012/09/08 19:04:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Aviv Shalgi\Application Data\DAEMON Tools Lite
[2013/06/29 19:23:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Aviv Shalgi\Application Data\DassaultSystemes
[2008/12/22 19:34:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Aviv Shalgi\Application Data\Design Science
[2014/01/18 16:27:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Aviv Shalgi\Application Data\Dropbox
[2013/11/02 15:23:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Aviv Shalgi\Application Data\Dropbox Folder Sync
[2010/11/20 11:20:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Aviv Shalgi\Application Data\EDrawings
[2011/08/28 16:06:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Aviv Shalgi\Application Data\go
[2009/11/09 18:36:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Aviv Shalgi\Application Data\ICAClient
[2008/10/29 13:32:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Aviv Shalgi\Application Data\ICQ
[2012/09/08 15:31:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Aviv Shalgi\Application Data\LockLizard
[2009/06/13 18:16:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Aviv Shalgi\Application Data\Maple
[2013/03/01 16:11:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Aviv Shalgi\Application Data\MSNInstaller
[2009/10/07 19:32:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Aviv Shalgi\Application Data\SMSender
[2013/10/14 21:55:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Aviv Shalgi\Application Data\Stardock
[2012/08/03 13:14:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Aviv Shalgi\Application Data\TeamViewer
[2009/09/14 13:29:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Aviv Shalgi\Application Data\Uniblue
[2011/11/11 13:57:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Aviv Shalgi\Application Data\Unity
[2013/12/09 23:58:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Aviv Shalgi\Application Data\uTorrent
[2012/05/01 21:54:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Aviv Shalgi\Application Data\WaveMetrics
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
< %USERPROFILE%\..|smtmp;true;true;true /FP >
 
< %temp%\smtmp\*.* /s > >
 
< MD5 for: EXPLORER.DESIGNER.VB  >
[2005/09/23 02:27:08 | 000,030,825 | ---- | M] () MD5=1B02BC8983576F2C80D2BE2BB97B9E97 -- C:\Documents and Settings\Aviv Shalgi\Application Data\Microsoft\VSTAHost\SolidWorks_VSTA\8.0\TemplatesCache\Item\VisualBasic\1033\Explorer.zip\explorer.designer.vb
 
< MD5 for: EXPLORER.EXE  >
[2008/04/14 02:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\explorer.exe
[2008/04/14 02:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2008/04/14 02:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- C:\WINDOWS\system32\dllcache\explorer.exe
[2007/12/31 12:03:18 | 001,033,216 | ---- | M] (Microsoft Corporation) MD5=7712DF0CDDE3A5AC89843E61CD5B3658 -- C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
 
< MD5 for: EXPLORER.EXE-082F38A9.PF  >
[2014/01/18 12:44:21 | 000,021,390 | ---- | M] () MD5=95ADF8BEE9BB61EC44F6CB5A434192FC -- C:\WINDOWS\Prefetch\EXPLORER.EXE-082F38A9.pf
 
< MD5 for: EXPLORER.RESX  >
[2005/09/23 02:27:08 | 000,040,553 | ---- | M] () MD5=B1B3C02B970204A703854F13D66A0C79 -- C:\Documents and Settings\Aviv Shalgi\Application Data\Microsoft\VSTAHost\SolidWorks_VSTA\8.0\TemplatesCache\Item\VisualBasic\1033\Explorer.zip\explorer.resx
 
< MD5 for: EXPLORER.SCF  >
[2004/08/04 14:00:00 | 000,000,080 | ---- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 -- C:\WINDOWS\explorer.scf
 
< MD5 for: EXPLORER.VB  >
[2005/09/23 02:27:08 | 000,007,236 | ---- | M] () MD5=0408BE3A764405BDF6120B13756C207B -- C:\Documents and Settings\Aviv Shalgi\Application Data\Microsoft\VSTAHost\SolidWorks_VSTA\8.0\TemplatesCache\Item\VisualBasic\1033\Explorer.zip\explorer.vb
 
< MD5 for: EXPLORER.VSTEMPLATE  >
[2005/09/23 02:27:08 | 000,001,333 | ---- | M] () MD5=9DD77EB173C4F605676D53074C1FAF9A -- C:\Documents and Settings\Aviv Shalgi\Application Data\Microsoft\VSTAHost\SolidWorks_VSTA\8.0\TemplatesCache\Item\VisualBasic\1033\Explorer.zip\explorer.vstemplate
 
< MD5 for: EXPLORER.ZIP  >
[2009/06/03 21:15:06 | 000,020,394 | ---- | M] () MD5=B469409C2B2A33C542190B720E11BD79 -- C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Explorer.zip
 
< MD5 for: IEXPLORE.CHM  >
[2009/02/21 00:21:24 | 000,529,818 | ---- | M] () MD5=1435F4731719DF5F57D17DC38196245D -- C:\WINDOWS\Help\iexplore.chm
[2007/12/31 12:06:39 | 000,503,758 | ---- | M] () MD5=652E46500C149D1DC948BF9CEA8C4933 -- C:\WINDOWS\ie8\iexplore.chm
 
< MD5 for: IEXPLORE.CHW  >
[2012/02/14 18:24:13 | 000,153,185 | ---- | M] () MD5=F6BF8EE85D45D4CAC077BA750FF2EF8A -- C:\WINDOWS\Help\iexplore.chw
 
< MD5 for: IEXPLORE.EXE  >
[2008/10/15 08:34:58 | 000,633,632 | ---- | M] (Microsoft Corporation) MD5=056C927CF7207857E8B34F7A8FFD9B9E -- C:\WINDOWS\ie7updates\KB961260-IE7\iexplore.exe
[2008/12/19 07:25:30 | 000,634,024 | ---- | M] (Microsoft Corporation) MD5=15E8A89499741D5CF59A9CF6463A4339 -- C:\WINDOWS\ie7updates\KB963027-IE7\iexplore.exe
[2008/04/14 02:12:22 | 000,093,184 | ---- | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 -- C:\WINDOWS\ServicePackFiles\i386\iexplore.exe
[2007/12/31 12:06:39 | 000,625,664 | ---- | M] (Microsoft Corporation) MD5=632BDE0179847234433CA50945442ACB -- C:\WINDOWS\ie7updates\KB953838-IE7\iexplore.exe
[2009/03/08 13:09:26 | 000,638,816 | ---- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E -- C:\Program Files\Internet Explorer\iexplore.exe
[2009/03/08 13:09:26 | 000,638,816 | ---- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E -- C:\WINDOWS\system32\dllcache\iexplore.exe
[2009/02/28 06:54:44 | 000,636,088 | ---- | M] (Microsoft Corporation) MD5=BCD8E48709BE4A79606F0B6E8E9A6162 -- C:\WINDOWS\$hf_mig$\KB963027-IE7\SP3QFE\iexplore.exe
[2009/02/28 06:54:44 | 000,636,088 | ---- | M] (Microsoft Corporation) MD5=BCD8E48709BE4A79606F0B6E8E9A6162 -- C:\WINDOWS\ie7updates\KB969897-IE7\iexplore.exe
[2009/04/25 07:27:39 | 000,636,088 | ---- | M] (Microsoft Corporation) MD5=C0503FD8D163652735C1EE900672A75C -- C:\WINDOWS\ie8\iexplore.exe
[2008/06/23 10:23:52 | 000,625,664 | ---- | M] (Microsoft Corporation) MD5=C52A9EF571E91535EB78DB4B8B95EA07 -- C:\WINDOWS\ie7updates\KB956390-IE7\iexplore.exe
[2008/08/23 07:56:16 | 000,635,848 | ---- | M] (Microsoft Corporation) MD5=E8305C30D35E85D6657ED3E9934CB302 -- C:\WINDOWS\ie7updates\KB958215-IE7\iexplore.exe
 
< MD5 for: IEXPLORE.EXE.MUI  >
[2009/03/08 13:21:44 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 -- C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2009/03/08 13:21:44 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 -- C:\Program Files\Internet Explorer\iexplore.exe.mui
[2007/12/31 12:06:40 | 000,573,440 | ---- | M] (Microsoft Corporation) MD5=B58D8A1C7EE0E922EC7D2616DA136FC3 -- C:\WINDOWS\ie8\iexplore.exe.mui
 
< MD5 for: IEXPLORE.EXE-27122324.PF  >
[2014/01/16 19:02:29 | 000,093,694 | ---- | M] () MD5=990F66FACA1091DE38014F0BCBE710E4 -- C:\WINDOWS\Prefetch\IEXPLORE.EXE-27122324.pf
 
< MD5 for: IEXPLORE.HLP  >
[2004/08/04 14:00:00 | 000,180,335 | ---- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 -- C:\WINDOWS\Help\iexplore.hlp
 
< MD5 for: SERVICES  >
[2004/08/04 14:00:00 | 000,007,116 | ---- | M] () MD5=95826940E657FE0567A8EC0F2A6AD11A -- C:\WINDOWS\system32\drivers\etc\services
 
< MD5 for: SERVICES.CFG  >
[2013/12/18 20:42:40 | 000,558,851 | ---- | M] () MD5=A044715A48D8FADB9366D554F20D3331 -- C:\Program Files\Adobe\Reader 10.0\Reader\Services\Services.cfg
[2011/06/06 12:55:30 | 000,584,045 | R--- | M] () MD5=B82DD53FA8C260DDD7FDC42182DB816E -- C:\WINDOWS\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\services.cfg
 
< MD5 for: SERVICES.EXE  >
[2009/02/06 13:06:24 | 000,110,592 | ---- | M] (Microsoft Corporation) MD5=020CEAAEDC8EB655B6506B8C70D53BB6 -- C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\services.exe
[2008/04/14 02:12:34 | 000,108,544 | ---- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 -- C:\WINDOWS\$NtUninstallKB956572$\services.exe
[2008/04/14 02:12:34 | 000,108,544 | ---- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 -- C:\WINDOWS\ServicePackFiles\i386\services.exe
[2009/02/06 13:11:05 | 000,110,592 | ---- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 -- C:\WINDOWS\system32\dllcache\services.exe
[2009/02/06 13:11:05 | 000,110,592 | ---- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 -- C:\WINDOWS\system32\services.exe
[2004/08/04 14:00:00 | 000,108,032 | ---- | M] (Microsoft Corporation) MD5=C6CE6EEC82F187615D1002BB3BB50ED4 -- C:\WINDOWS\$NtServicePackUninstall$\services.exe
 
< MD5 for: SERVICES.JSON  >
[2013/10/08 23:22:01 | 000,003,069 | ---- | M] () MD5=A862B522789C22C2E181E8C48749C8B8 -- C:\Documents and Settings\Aviv Shalgi\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\kdadialhpiikehpdeejjeiikopddkjem\1.0.3.8_0\config\services.json
 
< MD5 for: SERVICES.LNK  >
[2008/09/15 16:26:34 | 000,001,602 | ---- | M] () MD5=ED079D9630C9235FE7DEF97796C981A0 -- C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\Services.lnk
 
< MD5 for: SERVICES.MOCHIADS.COM.SOL  >
[2013/11/22 00:32:13 | 000,002,782 | ---- | M] () MD5=78408B0D0EB4E12767EF8BFAC4531688 -- C:\Documents and Settings\Aviv Shalgi\Local Settings\Application Data\Google\Chrome\User Data\Default\Pepper Data\Shockwave Flash\WritableRoot\#SharedObjects\LFHSCVGH\mochiads.com\services.mochiads.com.sol
[2012/07/27 16:16:41 | 000,007,617 | ---- | M] () MD5=98EA32A4A2DBD095C658DBCF663D650E -- C:\Documents and Settings\Aviv Shalgi\Application Data\Macromedia\Flash Player\#SharedObjects\DPCZQLEV\mochiads.com\services.mochiads.com.sol
 
< MD5 for: SERVICES.MSC  >
[2004/08/04 14:00:00 | 000,033,464 | ---- | M] () MD5=E8089AA2A6F7FEE89B38C1F2D77BA6C6 -- C:\WINDOWS\system32\services.msc
 
< MD5 for: WINLOGON.EXE  >
[2004/08/04 14:00:00 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE -- C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2008/04/14 02:12:39 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E -- C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/14 02:12:39 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E -- C:\WINDOWS\system32\dllcache\winlogon.exe
[2008/04/14 02:12:39 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E -- C:\WINDOWS\system32\winlogon.exe
 
< %SYSTEMDRIVE%\*.* >
[2011/07/30 22:38:16 | 000,001,024 | ---- | M] () -- C:\.rnd
[2013/11/07 17:36:45 | 000,373,598 | ---- | M] () -- C:\aaw7boot.log
[2010/04/10 20:03:52 | 000,004,098 | ---- | M] () -- C:\AlonHW1.c
[2008/09/15 16:21:27 | 000,000,321 | ---- | M] () -- C:\boo.ini
[2013/02/27 22:35:56 | 000,000,199 | RHS- | M] () -- C:\boot.ini
[2009/10/19 15:14:59 | 000,000,199 | ---- | M] () -- C:\boot.txt
[2010/11/22 23:14:11 | 000,650,010 | ---- | M] () -- C:\diode.lib
[2013/08/14 18:40:24 | 000,000,000 | ---- | M] () -- C:\END
[2011/11/17 19:33:36 | 000,460,824 | ---- | M] () -- C:\img2-001.raw
[2008/09/12 13:28:29 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2011/02/23 21:43:42 | 000,000,484 | ---- | M] () -- C:\LOG18E.log
[2008/09/12 13:28:29 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2008/09/04 02:11:24 | 000,054,600 | ---- | M] (BitTorrent, Inc.) -- C:\npbittorrent.dll
[2004/08/04 14:00:00 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2008/11/06 20:40:46 | 000,250,048 | RHS- | M] () -- C:\ntldr
[2014/01/18 15:57:28 | 2145,386,496 | -HS- | M] () -- C:\pagefile.sys
[2008/09/12 12:36:50 | 000,000,522 | ---- | M] () -- C:\RHDSetup.log
[2009/09/14 14:08:08 | 000,005,046 | ---- | M] () -- C:\RootRepeal report 09-14-09 (15-08-08).txt
[2009/10/06 12:39:09 | 000,005,938 | ---- | M] () -- C:\RootRepeal report 10-06-09 (12-39-09).txt
[2008/11/12 23:17:15 | 000,000,232 | -H-- | M] () -- C:\sqmdata00.sqm
[2008/11/13 00:08:17 | 000,000,232 | -H-- | M] () -- C:\sqmdata01.sqm
[2008/11/29 04:09:16 | 000,000,232 | -H-- | M] () -- C:\sqmdata02.sqm
[2009/01/12 22:49:12 | 000,000,232 | -H-- | M] () -- C:\sqmdata03.sqm
[2009/01/13 22:24:44 | 000,000,232 | -H-- | M] () -- C:\sqmdata04.sqm
[2009/02/12 19:42:54 | 000,000,232 | -H-- | M] () -- C:\sqmdata05.sqm
[2008/11/12 23:17:15 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt00.sqm
[2008/11/13 00:08:17 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt01.sqm
[2008/11/29 04:09:16 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt02.sqm
[2009/01/12 22:49:12 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt03.sqm
[2009/01/13 22:24:44 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt04.sqm
[2009/02/12 19:42:54 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt05.sqm
[1 C:\*.tmp files -> C:\*.tmp -> ]
 
< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
 
< %systemroot%\Fonts\*.dll >
 
< %systemroot%\Fonts\*.ini >
[2008/09/15 16:26:05 | 000,000,067 | -HS- | M] () -- C:\WINDOWS\Fonts\desktop.ini
 
< %systemroot%\Fonts\*.ini2 >
 
< %systemroot%\Fonts\*.exe >
 
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 14:06:10 | 000,089,088 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2013/12/17 20:36:33 | 000,053,064 | ---- | M] (LogMeIn, Inc.) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\LMIproc.dll
[2002/11/15 06:28:04 | 000,077,824 | ---- | M] (Lexmark International) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\LXBAPP5C.DLL
[2008/07/06 12:50:03 | 000,597,504 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
 
< %systemroot%\REPAIR\*.bak1 >
 
< %systemroot%\REPAIR\*.ini >
 
< %systemroot%\system32\*.jpg >
 
< %systemroot%\*.jpg >
[2009/08/21 01:04:09 | 000,113,035 | ---- | M] () -- C:\WINDOWS\c2.jpg
[2009/08/21 01:04:12 | 000,113,035 | ---- | M] () -- C:\WINDOWS\c2_esr.jpg
[2009/08/20 19:47:04 | 000,182,012 | ---- | M] () -- C:\WINDOWS\c3.jpg
[2009/08/20 19:47:08 | 000,182,012 | ---- | M] () -- C:\WINDOWS\c5.jpg
[2009/08/20 19:46:53 | 000,131,793 | ---- | M] () -- C:\WINDOWS\eit_171.jpg
[2009/08/20 19:46:55 | 000,149,477 | ---- | M] () -- C:\WINDOWS\eit_195.jpg
[2009/08/21 01:04:05 | 000,191,657 | ---- | M] () -- C:\WINDOWS\eit_284.jpg
[2009/08/21 01:04:08 | 000,170,608 | ---- | M] () -- C:\WINDOWS\eit_304.jpg
[2009/08/20 19:47:10 | 000,131,793 | ---- | M] () -- C:\WINDOWS\eit_esr.jpg
[2009/08/20 15:30:24 | 000,155,357 | ---- | M] () -- C:\WINDOWS\mdi_igr.jpg
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
 
< %systemroot%\*.png >
 
< %systemroot%\*.scr >
[1999/10/25 08:50:04 | 000,180,354 | ---- | M] () -- C:\WINDOWS\SOHO Live Images.scr
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
 
< %systemroot%\*._sy >
[2008/11/06 16:49:17 | 000,013,248 | ---- | M] () -- C:\WINDOWS\jamutimaj._sy
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
 
< %APPDATA%\Adobe\Update\*.* >
 
< %ALLUSERSPROFILE%\Favorites\*.* >
 
< %APPDATA%\Microsoft\*.* >
 
< %PROGRAMFILES%\*.* >
 
< %APPDATA%\Update\*.* >
 
< %systemroot%\*. /mp /s >
 
< dir "%systemdrive%\*" /S /A:L /C >
 Volume in drive C has no label.
 Volume Serial Number is 44D3-9EF0
 Directory of C:\WINDOWS\assembly\GAC_32\System.EnterpriseServices
05/12/2009  11:28 PM    <JUNCTION>     2.0.0.0__b03f5f7f11d50a3a
               0 File(s)              0 bytes
 Directory of C:\WINDOWS\assembly\GAC_MSIL\IEExecRemote
05/12/2009  11:29 PM    <JUNCTION>     2.0.0.0__b03f5f7f11d50a3a
               0 File(s)              0 bytes
 Directory of C:\WINDOWS\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices
11/02/2013  03:19 PM    <JUNCTION>     v4.0_4.0.0.0__b03f5f7f11d50a3a
               0 File(s)              0 bytes
     Total Files Listed:
               0 File(s)              0 bytes
               3 Dir(s)  14,317,260,800 bytes free
 
< %systemroot%\System32\config\*.sav >
[2008/09/15 20:42:33 | 000,262,144 | ---- | M] () -- C:\WINDOWS\System32\config\default.sav
[2008/09/15 11:10:13 | 000,262,144 | ---- | M] () -- C:\WINDOWS\System32\config\security.sav
[2008/09/15 20:42:33 | 016,515,072 | ---- | M] () -- C:\WINDOWS\System32\config\software.sav
[2008/09/15 20:42:33 | 004,456,448 | ---- | M] () -- C:\WINDOWS\System32\config\system.sav
 
< %PROGRAMFILES%\bak. /s >
 
< %systemroot%\system32\bak. /s >
 
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/11/06 20:45:37 | 000,000,272 | -HS- | M] () -- C:\Documents and Settings\All Users\Start Menu\desktop.ini
 
< %systemroot%\system32\config\systemprofile\*.dat /x >
 
< %systemroot%\*.config >
 
< %systemroot%\system32\*.db >
 
< %PROGRAMFILES%\Internet Explorer\*.dat >
 
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2008/09/12 13:33:56 | 000,000,060 | -HS- | M] () -- C:\Documents and Settings\Aviv Shalgi\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2008/09/12 13:33:56 | 000,000,079 | ---- | M] () -- C:\Documents and Settings\Aviv Shalgi\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
 
< %USERPROFILE%\Desktop\*.exe >
[2014/01/18 16:27:44 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Aviv Shalgi\Desktop\OTL.exe
 
< %PROGRAMFILES%\Common Files\*.* >
 
< %systemroot%\*.src >
[2007/04/10 23:46:53 | 000,013,023 | ---- | M] () -- C:\WINDOWS\VX1000.src
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
 
< %systemroot%\install\*.* >
 
< %systemroot%\system32\DLL\*.* >
 
< %systemroot%\system32\HelpFiles\*.* >
 
< %systemroot%\system32\rundll\*.* >
 
< %systemroot%\winn32\*.* >
 
< %systemroot%\Java\*.* >
 
< %systemroot%\system32\test\*.* >
 
< %systemroot%\system32\Rundll32\*.* >
 
< %systemroot%\AppPatch\Custom\*.* >
 
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
 
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2009-06-16 08:47:52
 
========== Files - Unicode (All) ==========
[2014/01/18 15:49:10 | 000,000,000 | ---D | M](D:\Dropbox\My Documents\??????) -- D:\Dropbox\My Documents\השקעות
[2014/01/16 11:25:32 | 000,000,000 | ---D | M](C:\Documents and Settings\Aviv Shalgi\Desktop\?????) -- C:\Documents and Settings\Aviv Shalgi\Desktop\איילת
[2014/01/14 19:26:57 | 000,092,879 | ---- | M] ()(C:\Documents and Settings\Aviv Shalgi\Desktop\????? ???? - ????? ?? ???.pdf) -- C:\Documents and Settings\Aviv Shalgi\Desktop\קורות חיים - איילת בן דור.pdf
[2014/01/14 19:26:53 | 000,092,879 | ---- | C] ()(C:\Documents and Settings\Aviv Shalgi\Desktop\????? ???? - ????? ?? ???.pdf) -- C:\Documents and Settings\Aviv Shalgi\Desktop\קורות חיים - איילת בן דור.pdf
[2014/01/13 21:29:48 | 000,244,590 | ---- | M] ()(C:\Documents and Settings\Aviv Shalgi\Desktop\????? ???? - ???? ????? ???????.jpg) -- C:\Documents and Settings\Aviv Shalgi\Desktop\מערבי מירה - מסמך מרופא חניכיים.jpg
[2014/01/13 21:29:48 | 000,244,590 | ---- | C] ()(C:\Documents and Settings\Aviv Shalgi\Desktop\????? ???? - ???? ????? ???????.jpg) -- C:\Documents and Settings\Aviv Shalgi\Desktop\מערבי מירה - מסמך מרופא חניכיים.jpg
[2014/01/13 16:24:41 | 000,570,880 | ---- | M] ()(D:\Dropbox\My Documents\???? ??????? - ????? ????? ??????.jpg) -- D:\Dropbox\My Documents\אלון רוזנברג - עדכון פרטים אישיים.jpg
[2014/01/13 16:24:41 | 000,570,880 | ---- | C] ()(D:\Dropbox\My Documents\???? ??????? - ????? ????? ??????.jpg) -- D:\Dropbox\My Documents\אלון רוזנברג - עדכון פרטים אישיים.jpg
[2014/01/09 20:04:06 | 000,027,648 | ---- | M] ()(D:\Dropbox\My Documents\????? ???? - ?????.doc) -- D:\Dropbox\My Documents\המלצה לנטע - איילת.doc
[2014/01/09 19:52:09 | 000,027,648 | ---- | C] ()(D:\Dropbox\My Documents\????? ???? - ?????.doc) -- D:\Dropbox\My Documents\המלצה לנטע - איילת.doc
[2014/01/05 20:33:34 | 000,000,000 | ---D | M](D:\Dropbox\My Documents\???) -- D:\Dropbox\My Documents\אמא
[2014/01/02 18:38:10 | 000,055,608 | ---- | M] ()(D:\Dropbox\My Documents\???? ????? ????.xlsx) -- D:\Dropbox\My Documents\שעות עבודה תאסק.xlsx
[2013/12/17 21:46:15 | 000,092,879 | ---- | M] ()(D:\Dropbox\My Documents\????? ???? - ????? ?? ???.pdf) -- D:\Dropbox\My Documents\קורות חיים - איילת בן דור.pdf
[2013/12/07 20:44:40 | 000,000,000 | ---D | M](D:\Dropbox\My Documents\????? ????) -- D:\Dropbox\My Documents\קורות חיים
[2013/12/07 19:46:01 | 000,000,000 | ---D | M](D:\Dropbox\My Documents\???? ???????) -- D:\Dropbox\My Documents\דירה במרגנית
[2013/12/07 19:10:36 | 000,000,000 | ---D | M](D:\Dropbox\My Documents\???) -- D:\Dropbox\My Documents\צבא
[2013/12/06 23:00:42 | 000,009,120 | ---- | M] ()(C:\Documents and Settings\Aviv Shalgi\Desktop\?????? ????????.xlsx) -- C:\Documents and Settings\Aviv Shalgi\Desktop\מטבעות מעניינים.xlsx
[2013/12/06 22:10:28 | 000,009,120 | ---- | C] ()(C:\Documents and Settings\Aviv Shalgi\Desktop\?????? ????????.xlsx) -- C:\Documents and Settings\Aviv Shalgi\Desktop\מטבעות מעניינים.xlsx
[2013/12/06 18:23:50 | 000,017,535 | ---- | M] ()(C:\Documents and Settings\Aviv Shalgi\Desktop\????? ????????.xlsx) -- C:\Documents and Settings\Aviv Shalgi\Desktop\חברות מעניינות.xlsx
[2013/12/04 22:49:07 | 000,022,723 | ---- | M] ()(D:\Dropbox\My Documents\????? ???? - ????? ?? ???.docx) -- D:\Dropbox\My Documents\קורות חיים - איילת בן דור.docx
[2013/12/03 20:31:43 | 000,000,165 | -H-- | M] ()(C:\Documents and Settings\Aviv Shalgi\Desktop\~$????? ????????.xlsx) -- C:\Documents and Settings\Aviv Shalgi\Desktop\~$חברות מעניינות.xlsx
[2013/12/03 20:31:43 | 000,000,165 | -H-- | C] ()(C:\Documents and Settings\Aviv Shalgi\Desktop\~$????? ????????.xlsx) -- C:\Documents and Settings\Aviv Shalgi\Desktop\~$חברות מעניינות.xlsx
[2013/11/20 23:33:59 | 000,042,827 | ---- | M] ()(D:\Dropbox\My Documents\????? ?????? ???? 14 29.12.12 ??? ????.pdf) -- D:\Dropbox\My Documents\תכנית עדכנית קומה 14 29.12.12 ללא רהוט.pdf
[2013/11/20 23:33:59 | 000,042,827 | ---- | C] ()(D:\Dropbox\My Documents\????? ?????? ???? 14 29.12.12 ??? ????.pdf) -- D:\Dropbox\My Documents\תכנית עדכנית קומה 14 29.12.12 ללא רהוט.pdf
[2013/11/20 23:33:28 | 000,050,646 | ---- | M] ()(D:\Dropbox\My Documents\????? ?????? ???? 14 29.12.12.pdf) -- D:\Dropbox\My Documents\תכנית עדכנית קומה 14 29.12.12.pdf
[2013/11/20 23:33:27 | 000,050,646 | ---- | C] ()(D:\Dropbox\My Documents\????? ?????? ???? 14 29.12.12.pdf) -- D:\Dropbox\My Documents\תכנית עדכנית קומה 14 29.12.12.pdf
[2013/11/19 19:37:31 | 000,000,000 | ---D | M](D:\Dropbox\My Documents\????? ?????? ??????) -- D:\Dropbox\My Documents\פנסיה וביטוח מנהלים
[2013/11/09 17:54:09 | 000,518,480 | ---- | M] ()(C:\Documents and Settings\Aviv Shalgi\Desktop\?? ???? ?????? ?????? ???? ???????.pdf) -- C:\Documents and Settings\Aviv Shalgi\Desktop\כך תגבה מחירים גבוהים עבור שירותיך.pdf
[2013/11/09 17:54:09 | 000,518,480 | ---- | C] ()(C:\Documents and Settings\Aviv Shalgi\Desktop\?? ???? ?????? ?????? ???? ???????.pdf) -- C:\Documents and Settings\Aviv Shalgi\Desktop\כך תגבה מחירים גבוהים עבור שירותיך.pdf
[2013/11/02 16:20:00 | 000,000,000 | ---D | M](D:\Dropbox\My Documents\???) -- D:\Dropbox\My Documents\אבא
[2013/11/02 16:12:47 | 000,000,000 | ---D | M](D:\Dropbox\My Documents\?????? ????? - ????) -- D:\Dropbox\My Documents\אולטרה סאונד - רעות
[2013/11/02 16:12:47 | 000,000,000 | ---D | C](D:\Dropbox\My Documents\???) -- D:\Dropbox\My Documents\אבא
[2013/11/02 16:12:43 | 000,000,000 | ---D | M](D:\Dropbox\My Documents\?????? ????? ????? 5.4.11) -- D:\Dropbox\My Documents\אולטרה סאונד מרעות 5.4.11
[2013/11/02 16:12:43 | 000,000,000 | ---D | C](D:\Dropbox\My Documents\?????? ????? - ????) -- D:\Dropbox\My Documents\אולטרה סאונד - רעות
[2013/11/02 16:12:41 | 000,000,000 | ---D | M](D:\Dropbox\My Documents\?????) -- D:\Dropbox\My Documents\אינטל
[2013/11/02 16:12:41 | 000,000,000 | ---D | C](D:\Dropbox\My Documents\?????? ????? ????? 5.4.11) -- D:\Dropbox\My Documents\אולטרה סאונד מרעות 5.4.11
[2013/11/02 16:12:33 | 000,000,000 | ---D | C](D:\Dropbox\My Documents\?????) -- D:\Dropbox\My Documents\אינטל
[2013/11/02 16:12:28 | 000,000,000 | ---D | C](D:\Dropbox\My Documents\???) -- D:\Dropbox\My Documents\אמא
[2013/11/02 16:12:24 | 000,000,000 | ---D | C](D:\Dropbox\My Documents\???? ???????) -- D:\Dropbox\My Documents\דירה במרגנית
[2013/11/02 16:12:23 | 000,000,000 | ---D | M](D:\Dropbox\My Documents\???? ???? ????) -- D:\Dropbox\My Documents\דירה בעמק ברכה
[2013/11/02 16:12:22 | 000,000,000 | ---D | M](D:\Dropbox\My Documents\???? ???? ??? - ?????) -- D:\Dropbox\My Documents\הסכם חוזה מכר - גינדי
[2013/11/02 16:12:22 | 000,000,000 | ---D | C](D:\Dropbox\My Documents\???? ???? ????) -- D:\Dropbox\My Documents\דירה בעמק ברכה
[2013/11/02 16:12:16 | 000,000,000 | ---D | C](D:\Dropbox\My Documents\???? ???? ??? - ?????) -- D:\Dropbox\My Documents\הסכם חוזה מכר - גינדי
[2013/11/02 16:12:04 | 000,000,000 | ---D | M](D:\Dropbox\My Documents\?????? ??? ???????) -- D:\Dropbox\My Documents\הקבצים שלי שהתקבלו
[2013/11/02 16:12:04 | 000,000,000 | ---D | C](D:\Dropbox\My Documents\?????? ??? ???????) -- D:\Dropbox\My Documents\הקבצים שלי שהתקבלו
[2013/11/02 16:11:02 | 000,000,000 | ---D | C](D:\Dropbox\My Documents\??????) -- D:\Dropbox\My Documents\השקעות
[2013/11/02 16:11:01 | 000,000,000 | ---D | M](D:\Dropbox\My Documents\???? ????? - ???? ???????) -- D:\Dropbox\My Documents\חוזה יוחנן - רעות וההורים
[2013/11/02 16:10:55 | 000,000,000 | ---D | C](D:\Dropbox\My Documents\???? ????? - ???? ???????) -- D:\Dropbox\My Documents\חוזה יוחנן - רעות וההורים
[2013/11/02 16:10:53 | 000,000,000 | ---D | M](D:\Dropbox\My Documents\???? ??????) -- D:\Dropbox\My Documents\חוזה שכירות
[2013/11/02 16:10:34 | 000,000,000 | ---D | M](D:\Dropbox\My Documents\?????) -- D:\Dropbox\My Documents\יזמות
[2013/11/02 16:10:34 | 000,000,000 | ---D | C](D:\Dropbox\My Documents\???? ??????) -- D:\Dropbox\My Documents\חוזה שכירות
[2013/11/02 16:09:38 | 000,000,000 | ---D | C](D:\Dropbox\My Documents\?????) -- D:\Dropbox\My Documents\יזמות
[2013/11/02 16:09:37 | 000,000,000 | ---D | M](D:\Dropbox\My Documents\???????) -- D:\Dropbox\My Documents\לימודים
[2013/11/02 16:09:33 | 000,000,000 | ---D | M](D:\Dropbox\My Documents\?????? ??????) -- D:\Dropbox\My Documents\מסמכים לנסיעה
[2013/11/02 16:09:33 | 000,000,000 | ---D | C](D:\Dropbox\My Documents\???????) -- D:\Dropbox\My Documents\לימודים
[2013/11/02 16:09:32 | 000,000,000 | ---D | M](D:\Dropbox\My Documents\?????? ?? ??? 2) -- D:\Dropbox\My Documents\מסמכים על תמא 2
[2013/11/02 16:09:32 | 000,000,000 | ---D | C](D:\Dropbox\My Documents\?????? ??????) -- D:\Dropbox\My Documents\מסמכים לנסיעה
[2013/11/02 16:09:30 | 000,000,000 | ---D | C](D:\Dropbox\My Documents\?????? ?? ??? 2) -- D:\Dropbox\My Documents\מסמכים על תמא 2
[2013/11/02 16:09:28 | 000,000,000 | ---D | M](D:\Dropbox\My Documents\????) -- D:\Dropbox\My Documents\סבתא
[2013/11/02 16:09:25 | 000,000,000 | ---D | M](D:\Dropbox\My Documents\????? ???? ?? ???? ?????? ?????? ??????? ????) -- D:\Dropbox\My Documents\סריקת מסמך של סבתא לשירות ממשלתי לניצולי שואה
[2013/11/02 16:09:25 | 000,000,000 | ---D | C](D:\Dropbox\My Documents\????) -- D:\Dropbox\My Documents\סבתא
[2013/11/02 16:09:24 | 000,000,000 | ---D | M](D:\Dropbox\My Documents\???? - ???? ?????) -- D:\Dropbox\My Documents\פדקס - ויזה לאלון
[2013/11/02 16:09:24 | 000,000,000 | ---D | C](D:\Dropbox\My Documents\????? ???? ?? ???? ?????? ?????? ??????? ????) -- D:\Dropbox\My Documents\סריקת מסמך של סבתא לשירות ממשלתי לניצולי שואה
[2013/11/02 16:09:24 | 000,000,000 | ---D | C](D:\Dropbox\My Documents\???? - ???? ?????) -- D:\Dropbox\My Documents\פדקס - ויזה לאלון
[2013/11/02 16:09:19 | 000,000,000 | ---D | C](D:\Dropbox\My Documents\????? ?????? ??????) -- D:\Dropbox\My Documents\פנסיה וביטוח מנהלים
[2013/11/02 16:09:19 | 000,000,000 | ---D | C](D:\Dropbox\My Documents\???) -- D:\Dropbox\My Documents\צבא
[2013/11/02 16:09:15 | 000,000,000 | ---D | M](D:\Dropbox\My Documents\???) -- D:\Dropbox\My Documents\קיה
[2013/11/02 16:09:15 | 000,000,000 | ---D | C](D:\Dropbox\My Documents\????? ????) -- D:\Dropbox\My Documents\קורות חיים
[2013/11/02 16:09:14 | 000,000,000 | ---D | C](D:\Dropbox\My Documents\???) -- D:\Dropbox\My Documents\קיה
[2013/11/02 16:09:12 | 000,000,000 | ---D | M](D:\Dropbox\My Documents\??? ?????) -- D:\Dropbox\My Documents\קרן הגשמה
[2013/11/02 16:09:10 | 000,000,000 | ---D | M](D:\Dropbox\My Documents\????? ?????) -- D:\Dropbox\My Documents\שחזור ראוטר
[2013/11/02 16:09:10 | 000,000,000 | ---D | C](D:\Dropbox\My Documents\????? ?????) -- D:\Dropbox\My Documents\שחזור ראוטר
[2013/11/02 16:09:10 | 000,000,000 | ---D | C](D:\Dropbox\My Documents\??? ?????) -- D:\Dropbox\My Documents\קרן הגשמה
[2013/11/02 16:09:09 | 000,000,000 | ---D | M](D:\Dropbox\My Documents\????? ??? ?-5.3) -- D:\Dropbox\My Documents\תאונה קלה ב-5.3
[2013/11/02 16:09:05 | 000,000,000 | ---D | M](D:\Dropbox\My Documents\????) -- D:\Dropbox\My Documents\תארו
[2013/11/02 16:09:05 | 000,000,000 | ---D | C](D:\Dropbox\My Documents\????? ??? ?-5.3) -- D:\Dropbox\My Documents\תאונה קלה ב-5.3
[2013/11/02 16:09:03 | 000,000,000 | ---D | M](D:\Dropbox\My Documents\??????? ????) -- D:\Dropbox\My Documents\תוכניות דירה
[2013/11/02 16:09:03 | 000,000,000 | ---D | C](D:\Dropbox\My Documents\????) -- D:\Dropbox\My Documents\תארו
[2013/11/02 16:09:02 | 000,122,681 | ---- | C] ()(D:\Dropbox\My Documents\????? ????? ????? 2009.jpg) -- D:\Dropbox\My Documents\תעודת ביטוח לאוטו 2009.jpg
[2013/11/02 16:09:02 | 000,116,503 | ---- | C] ()(D:\Dropbox\My Documents\????? ??? - ????.pdf) -- D:\Dropbox\My Documents\תשלום קנס - אביב.pdf
[2013/11/02 16:09:02 | 000,089,648 | ---- | C] ()(D:\Dropbox\My Documents\????? ???? ?? ????.jpg) -- D:\Dropbox\My Documents\תעודת זהות של סבתא.jpg
[2013/11/02 16:09:02 | 000,084,016 | ---- | C] ()(D:\Dropbox\My Documents\????? ???? ?? ???? 2.jpg) -- D:\Dropbox\My Documents\תעודת זהות של סבתא 2.jpg
[2013/11/02 16:09:02 | 000,029,696 | ---- | C] ()(D:\Dropbox\My Documents\????? ???? - ???? ??? ?? ????? ????? ????? ???? - 12.08.doc) -- D:\Dropbox\My Documents\תמלול מקרה - קבלת דוח אי חגירת חגורה מאחור בנמל - 12.08.doc
[2013/11/02 16:09:02 | 000,000,000 | ---D | C](D:\Dropbox\My Documents\??????? ????) -- D:\Dropbox\My Documents\תוכניות דירה
[2013/11/02 16:09:01 | 005,595,695 | ---- | C] ()(D:\Dropbox\My Documents\???? ?????.pdf) -- D:\Dropbox\My Documents\קורס יזמות.pdf
[2013/11/02 16:09:01 | 000,612,613 | ---- | C] ()(D:\Dropbox\My Documents\????? ???????.pdf) -- D:\Dropbox\My Documents\תביעת מילואים.pdf
[2013/11/02 16:09:01 | 000,343,720 | ---- | C] ()(D:\Dropbox\My Documents\?????? ????? ????.jpg) -- D:\Dropbox\My Documents\שירותי תיווך מענת.jpg
[2013/11/02 16:09:01 | 000,322,038 | ---- | C] ()(D:\Dropbox\My Documents\?????? ??? - ???.jpg) -- D:\Dropbox\My Documents\רישיון רכב - קיה.jpg
[2013/11/02 16:09:01 | 000,284,905 | ---- | C] ()(D:\Dropbox\My Documents\?? ???.jpg) -- D:\Dropbox\My Documents\תז אבא.jpg
[2013/11/02 16:09:01 | 000,222,141 | ---- | C] ()(D:\Dropbox\My Documents\?? ?? ????.jpg) -- D:\Dropbox\My Documents\תז של סבתא.jpg
[2013/11/02 16:09:01 | 000,193,536 | ---- | C] ()(D:\Dropbox\My Documents\????? ??????? ???? ????? ?????.doc) -- D:\Dropbox\My Documents\רשימת מוזמנים ליום הולדת ביאיא.doc
[2013/11/02 16:09:01 | 000,173,458 | ---- | C] ()(D:\Dropbox\My Documents\??? ????? ?????.jpg) -- D:\Dropbox\My Documents\שכר לימוד לאייל.jpg
[2013/11/02 16:09:01 | 000,165,823 | ---- | C] ()(D:\Dropbox\My Documents\?? ???? ??? - ????.jpg) -- D:\Dropbox\My Documents\תז וספח מלא - אביב.jpg
[2013/11/02 16:09:01 | 000,145,516 | ---- | C] ()(D:\Dropbox\My Documents\??? ??????? ???? 2.jpg) -- D:\Dropbox\My Documents\קרן השתלמות רעות 2.jpg
[2013/11/02 16:09:01 | 000,143,424 | ---- | C] ()(D:\Dropbox\My Documents\???? ?????????.pdf) -- D:\Dropbox\My Documents\שובר לקורדיליה.pdf
[2013/11/02 16:09:01 | 000,061,841 | ---- | C] ()(D:\Dropbox\My Documents\?????? ?? ???.jpg) -- D:\Dropbox\My Documents\רישיון של אמא.jpg
[2013/11/02 16:09:01 | 000,060,217 | ---- | C] ()(D:\Dropbox\My Documents\?????? ????? - ????.jpg) -- D:\Dropbox\My Documents\רישיון נהיגה - אביב.jpg
[2013/11/02 16:09:01 | 000,055,608 | ---- | C] ()(D:\Dropbox\My Documents\???? ????? ????.xlsx) -- D:\Dropbox\My Documents\שעות עבודה תאסק.xlsx
[2013/11/02 16:09:01 | 000,035,328 | ---- | C] ()(D:\Dropbox\My Documents\??? 38 - ????.doc) -- D:\Dropbox\My Documents\תמא 38 - רעות.doc
[2013/11/02 16:09:01 | 000,029,696 | ---- | C] ()(D:\Dropbox\My Documents\??????? ??????.ppt) -- D:\Dropbox\My Documents\שיעורים פרטיים.ppt
[2013/11/02 16:09:01 | 000,028,160 | ---- | C] ()(D:\Dropbox\My Documents\????? ????????? ?????? ?????.xls) -- D:\Dropbox\My Documents\רשימה לסטודנטים למסיבת חנוכה.xls
[2013/11/02 16:09:01 | 000,027,648 | ---- | C] ()(D:\Dropbox\My Documents\????? ??????? ???? ????? ?????.xls) -- D:\Dropbox\My Documents\רשימת מוזמנים ליום הולדת ביאיא.xls
[2013/11/02 16:09:01 | 000,026,112 | ---- | C] ()(D:\Dropbox\My Documents\????? ?????? ?? ??? ????? ??? ?? ????? ?????.doc) -- D:\Dropbox\My Documents\תמלול השיחות עם יאן וחברה שלו על מכירת האוטו.doc
[2013/11/02 16:09:01 | 000,024,576 | ---- | C] ()(D:\Dropbox\My Documents\???? ????? ????.xls) -- D:\Dropbox\My Documents\שעות עבודה בצבא.xls
[2013/11/02 16:09:01 | 000,023,040 | ---- | C] ()(D:\Dropbox\My Documents\???? ?-GMAT.doc) -- D:\Dropbox\My Documents\שאלה ב-GMAT.doc
[2013/11/02 16:09:01 | 000,017,789 | ---- | C] ()(D:\Dropbox\My Documents\????? ??????? ???.xlsx) -- D:\Dropbox\My Documents\רשימת התקשרות ועד.xlsx
[2013/11/02 16:09:01 | 000,000,921 | ---- | C] ()(D:\Dropbox\My Documents\?????? ?????? ???.lnk) -- D:\Dropbox\My Documents\תיקיות השיתוף שלי.lnk
[2013/11/02 16:09:00 | 000,092,879 | ---- | C] ()(D:\Dropbox\My Documents\????? ???? - ????? ?? ???.pdf) -- D:\Dropbox\My Documents\קורות חיים - איילת בן דור.pdf
[2013/11/02 16:09:00 | 000,022,723 | ---- | C] ()(D:\Dropbox\My Documents\????? ???? - ????? ?? ???.docx) -- D:\Dropbox\My Documents\קורות חיים - איילת בן דור.docx
[2013/11/02 16:09:00 | 000,014,848 | ---- | C] ()(D:\Dropbox\My Documents\???? ??????.xls) -- D:\Dropbox\My Documents\קובץ ממאורה.xls
[2013/11/02 16:08:59 | 000,612,004 | ---- | C] ()(D:\Dropbox\My Documents\?? ??????? 12.01.12.jpg) -- D:\Dropbox\My Documents\צו מילואים 12.01.12.jpg
[2013/11/02 16:08:59 | 000,343,040 | ---- | C] ()(D:\Dropbox\My Documents\???? ?????? ?? ???.ppt) -- D:\Dropbox\My Documents\קבלה ללפטופ של אבא.ppt
[2013/11/02 16:08:59 | 000,224,628 | ---- | C] ()(D:\Dropbox\My Documents\?? ????? ?? ???? ????.jpg) -- D:\Dropbox\My Documents\צק מבוטל של סבתא וסבא.jpg
[2013/11/02 16:08:59 | 000,147,456 | ---- | C] ()(D:\Dropbox\My Documents\???? ?? ?????.ppt) -- D:\Dropbox\My Documents\קאזה דה ברזיל.ppt
[2013/11/02 16:08:59 | 000,131,758 | ---- | C] ()(D:\Dropbox\My Documents\???? ?????? ?????.pdf) -- D:\Dropbox\My Documents\קבלה לנסיעה לאילת.pdf
[2013/11/02 16:08:59 | 000,031,744 | ---- | C] ()(D:\Dropbox\My Documents\??????? - ????? ??????.xls) -- D:\Dropbox\My Documents\ערעורים - שאלון למועמד.xls
[2013/11/02 16:08:59 | 000,015,676 | ---- | C] ()(D:\Dropbox\My Documents\????? ?? ????.docx) -- D:\Dropbox\My Documents\פוקצה של רועי.docx
[2013/11/02 16:08:59 | 000,011,824 | ---- | C] ()(D:\Dropbox\My Documents\???????? ?????.xlsx) -- D:\Dropbox\My Documents\פרויקטים בתאסק.xlsx
[2013/11/02 16:08:58 | 001,086,976 | ---- | C] ()(D:\Dropbox\My Documents\?????? ???? ?????.ppt) -- D:\Dropbox\My Documents\סריקות לקרן פנסיה.ppt
[2013/11/02 16:08:58 | 000,673,570 | ---- | C] ()(D:\Dropbox\My Documents\????? ???? ????? ?1945 - 2.jpg) -- D:\Dropbox\My Documents\סריקת מסמך לסבתא מ1945 - 2.jpg
[2013/11/02 16:08:58 | 000,517,688 | ---- | C] ()(D:\Dropbox\My Documents\????? ????? - ????? ????? ?????? 2.jpg) -- D:\Dropbox\My Documents\סריקה לסבתא - ארגון נפגעי הנאצים 2.jpg
[2013/11/02 16:08:58 | 000,452,854 | ---- | C] ()(D:\Dropbox\My Documents\????? ???? ????? ?1945.jpg) -- D:\Dropbox\My Documents\סריקת מסמך לסבתא מ1945.jpg
[2013/11/02 16:08:58 | 000,416,841 | ---- | C] ()(D:\Dropbox\My Documents\????? ????? - ????? ????? ??????.jpg) -- D:\Dropbox\My Documents\סריקה לסבתא - ארגון נפגעי הנאצים.jpg
[2013/11/02 16:08:58 | 000,265,824 | ---- | C] ()(D:\Dropbox\My Documents\???? ?? ?????? ??????? - 1070088924.pdf) -- D:\Dropbox\My Documents\סירק דו סולייל כרטיסים - 1070088924.pdf
[2013/11/02 16:08:58 | 000,146,007 | ---- | C] ()(D:\Dropbox\My Documents\????? ??????.jpg) -- D:\Dropbox\My Documents\סריקת דולרים.jpg
[2013/11/02 16:08:58 | 000,104,376 | ---- | C] ()(D:\Dropbox\My Documents\?????????.jpg) -- D:\Dropbox\My Documents\סמארטקלאב.jpg
[2013/11/02 16:08:58 | 000,024,576 | ---- | C] ()(D:\Dropbox\My Documents\????? ????? 19.05.10.doc) -- D:\Dropbox\My Documents\ערעור לסבתא 19.05.10.doc
[2013/11/02 16:08:58 | 000,014,080 | ---- | C] ()(D:\Dropbox\My Documents\????? ????.docx) -- D:\Dropbox\My Documents\סמארט קלאב.docx
[2013/11/02 16:08:57 | 000,156,146 | ---- | C] ()(D:\Dropbox\My Documents\??? ??.jpg) -- D:\Dropbox\My Documents\סבא תז.jpg
[2013/11/02 16:08:57 | 000,146,498 | ---- | C] ()(D:\Dropbox\My Documents\????? ???? ?????.jpg) -- D:\Dropbox\My Documents\משלוח ויזה לאלון.jpg
[2013/11/02 16:08:57 | 000,080,391 | ---- | C] ()(D:\Dropbox\My Documents\???? ??????? - ?????? ?????? ????? - ????? ?? ????? ?????.pdf) -- D:\Dropbox\My Documents\משרד התחבורה - תשלומי רישיון נהיגה - הודעה על ביצוע תשלום.pdf
[2013/11/02 16:08:57 | 000,029,184 | ---- | C] ()(D:\Dropbox\My Documents\???? ????? ?? ???? ????? 2010.doc) -- D:\Dropbox\My Documents\נספח לחוזה עם אמיר ויערה 2010.doc
[2013/11/02 16:08:57 | 000,028,160 | ---- | C] ()(D:\Dropbox\My Documents\????? ????????? ?????? ??????? ??????.doc) -- D:\Dropbox\My Documents\מתכון לטורטליני גבינות עגבניות ומרווה.doc
[2013/11/02 16:08:57 | 000,028,160 | ---- | C] ()(D:\Dropbox\My Documents\???? ????? ?? ????????? 2009.doc) -- D:\Dropbox\My Documents\נספח לחוזה עם גולדפינגר 2009.doc
[2013/11/02 16:08:57 | 000,021,415 | ---- | C] ()(D:\Dropbox\My Documents\??? ???? - ????? ?????? 3.pdf) -- D:\Dropbox\My Documents\נסח טאבו - מורדי הגטאות 3.pdf
[2013/11/02 16:08:57 | 000,013,575 | ---- | C] ()(D:\Dropbox\My Documents\???? - ???? ?????.docx) -- D:\Dropbox\My Documents\מעקה - דניה סיבוס.docx
[2013/11/02 16:08:57 | 000,001,036 | ---- | C] ()(D:\Dropbox\My Documents\????? ?????? ?? ????.xls.lnk) -- D:\Dropbox\My Documents\מתנות לחתונה של רעות.xls.lnk
[2013/11/02 16:08:56 | 000,903,680 | ---- | C] ()(D:\Dropbox\My Documents\?????? ???? ???????.doc) -- D:\Dropbox\My Documents\מסמכים לקרן השתלמות.doc
[2013/11/02 16:08:56 | 000,595,663 | ---- | C] ()(D:\Dropbox\My Documents\?????? ?????? ????? ???????????.docx) -- D:\Dropbox\My Documents\מסמכים לאישור חנייה באוניברסיטה.docx
[2013/11/02 16:08:56 | 000,327,739 | ---- | C] ()(D:\Dropbox\My Documents\???? ??????? 18.7.PDF) -- D:\Dropbox\My Documents\מכתב מפלאפון 18.7.PDF
[2013/11/02 16:08:56 | 000,081,636 | ---- | C] ()(D:\Dropbox\My Documents\???? ????????? ??????.pdf) -- D:\Dropbox\My Documents\מנוי סמסטריאלי לחניון.pdf
[2013/11/02 16:08:56 | 000,013,754 | ---- | C] ()(D:\Dropbox\My Documents\???? ??????? ?? ???? ???? ???? ?????? ??????.docx) -- D:\Dropbox\My Documents\מכתב לעיריית תל אביב בגין חיוב ארנונה ואגרות.docx
[2013/11/02 16:08:56 | 000,010,288 | ---- | C] ()(D:\Dropbox\My Documents\???? ???? ????? - ??.xlsx) -- D:\Dropbox\My Documents\מעקב גובה ומשקל - לי.xlsx
[2013/11/02 16:08:55 | 000,163,179 | ---- | C] ()(D:\Dropbox\My Documents\???? ??'???? ?????.jpg) -- D:\Dropbox\My Documents\מכתב לג'נרלי מסבתא.jpg
[2013/11/02 16:08:55 | 000,155,343 | ---- | C] ()(D:\Dropbox\My Documents\???? ???? ????.jpg) -- D:\Dropbox\My Documents\מכתב לחנה שובל.jpg
[2013/11/02 16:08:55 | 000,125,809 | ---- | C] ()(D:\Dropbox\My Documents\????? ??? ?? ???? ???? ???? ??? - ???.pdf) -- D:\Dropbox\My Documents\מיפוי עצם כל גופי כולל ספקט אגן - סבא.pdf
[2013/11/02 16:08:55 | 000,037,888 | ---- | C] ()(D:\Dropbox\My Documents\???? ??????? ???? ???????? - ?????? ??????? ???.doc) -- D:\Dropbox\My Documents\מכתב לסוכנות החלל הישראלית - ספונסר להתמחות קיץ.doc
[2013/11/02 16:08:55 | 000,030,208 | ---- | C] ()(D:\Dropbox\My Documents\???? ???? ?????? ?? ????.doc) -- D:\Dropbox\My Documents\מייל לגבי הפנסיה של אביב.doc
[2013/11/02 16:08:55 | 000,025,600 | ---- | C] ()(D:\Dropbox\My Documents\???? ????? ?????? - ????? ????? 2.doc) -- D:\Dropbox\My Documents\מכתב למשרד הרישוי - נהיגה מונעת 2.doc
[2013/11/02 16:08:55 | 000,024,064 | ---- | C] ()(D:\Dropbox\My Documents\????? ?????.doc) -- D:\Dropbox\My Documents\מטמון חמיצר.doc
[2013/11/02 16:08:55 | 000,015,053 | ---- | C] ()(D:\Dropbox\My Documents\???? ???????? ???? ???? ???????.docx) -- D:\Dropbox\My Documents\מכתב למזכירות ועדת הערר לארנונה.docx
[2013/11/02 16:08:55 | 000,012,800 | ---- | C] ()(D:\Dropbox\My Documents\????? ?? ?????.ppt) -- D:\Dropbox\My Documents\מכירה של האוטו.ppt
[2013/11/02 16:08:54 | 000,824,832 | ---- | C] ()(D:\Dropbox\My Documents\??? ????? 60 ????.doc) -- D:\Dropbox\My Documents\יום הולדת 60 ליעל.doc
[2013/11/02 16:08:54 | 000,626,999 | ---- | C] ()(D:\Dropbox\My Documents\????? ???? ?? ??? 2.jpg) -- D:\Dropbox\My Documents\כרטיס עובד של סבא 2.jpg
[2013/11/02 16:08:54 | 000,473,235 | ---- | C] ()(D:\Dropbox\My Documents\????? ???? ?? ??? 1.jpg) -- D:\Dropbox\My Documents\כרטיס עובד של סבא 1.jpg
[2013/11/02 16:08:54 | 000,279,752 | ---- | C] ()(D:\Dropbox\My Documents\???? ?????? ????? ?? ??????? ??????? 2009.pdf) -- D:\Dropbox\My Documents\טופס לביטוח לאומי על מילואים בספטמבר 2009.pdf
[2013/11/02 16:08:54 | 000,243,684 | ---- | C] ()(D:\Dropbox\My Documents\???? ?? ????? ?? ??? ?? ????.jpg) -- D:\Dropbox\My Documents\חוזה של החנות של אבא של סבתא.jpg
[2013/11/02 16:08:54 | 000,179,697 | ---- | C] ()(D:\Dropbox\My Documents\??????? ????? ???? 2.jpg) -- D:\Dropbox\My Documents\חשבונית אופיס דיפו 2.jpg
[2013/11/02 16:08:54 | 000,154,792 | ---- | C] ()(D:\Dropbox\My Documents\??????? - ????? - ???? ?? ?????.pdf) -- D:\Dropbox\My Documents\חשבונית - גרופר - קאזה דה ברזיל.pdf
[2013/11/02 16:08:54 | 000,123,212 | ---- | C] ()(D:\Dropbox\My Documents\??????? ????? ????.jpg) -- D:\Dropbox\My Documents\חשבונית אופיס דיפו.jpg
[2013/11/02 16:08:54 | 000,105,177 | ---- | C] ()(D:\Dropbox\My Documents\?????? ???? ????? ??????? 30.09.09.html) -- D:\Dropbox\My Documents\כרטיסי טיסה ומלון לבודפשט 30.09.09.html
[2013/11/02 16:08:54 | 000,104,960 | ---- | C] ()(D:\Dropbox\My Documents\???? ?????? - ????? - ????.doc) -- D:\Dropbox\My Documents\חוזה שכירות - מרפאה - סופי.doc
[2013/11/02 16:08:54 | 000,096,256 | ---- | C] ()(D:\Dropbox\My Documents\???? ?????? - ????? - ?????.doc) -- D:\Dropbox\My Documents\חוזה שכירות - מרפאה - טיוטא.doc
[2013/11/02 16:08:54 | 000,065,558 | ---- | C] ()(D:\Dropbox\My Documents\????? ??????? ???? ????.pdf) -- D:\Dropbox\My Documents\כרטיס אוטובוס בניו יורק.pdf
[2013/11/02 16:08:54 | 000,024,576 | ---- | C] ()(D:\Dropbox\My Documents\????? ????? ?????.xls) -- D:\Dropbox\My Documents\חישוב מלגות לרעות.xls
[2013/11/02 16:08:54 | 000,024,064 | ---- | C] ()(D:\Dropbox\My Documents\?????.doc) -- D:\Dropbox\My Documents\להראל.doc
[2013/11/02 16:08:54 | 000,016,138 | ---- | C] ()(D:\Dropbox\My Documents\???? 1.docx) -- D:\Dropbox\My Documents\מטלה 1.docx
[2013/11/02 16:08:54 | 000,010,333 | ---- | C] ()(D:\Dropbox\My Documents\??? ????? ?????.xlsx) -- D:\Dropbox\My Documents\ימי הולדת לקלרה.xlsx
[2013/11/02 16:08:53 | 001,061,888 | ---- | C] ()(D:\Dropbox\My Documents\???? ???? ????? ??????? - ????? ???.doc) -- D:\Dropbox\My Documents\הצעת מחיר מעלית חיצונית - איציק לוי.doc
[2013/11/02 16:08:53 | 000,040,960 | ---- | C] ()(D:\Dropbox\My Documents\???? ?????? - ??? ???.doc) -- D:\Dropbox\My Documents\חוזה למרפאה - שטר חוב.doc
[2013/11/02 16:08:53 | 000,034,304 | ---- | C] ()(D:\Dropbox\My Documents\???? ???? ??? 38-???????.doc) -- D:\Dropbox\My Documents\הצעת מחיר תמא 38-גבעתיים.doc
[2013/11/02 16:08:53 | 000,033,280 | ---- | C] ()(D:\Dropbox\My Documents\????? ????? ???? ????? ?????? ???.doc) -- D:\Dropbox\My Documents\זכרון דברים בדבר קניית ומכירת רכב.doc
[2013/11/02 16:08:53 | 000,030,208 | ---- | C] ()(D:\Dropbox\My Documents\???????? ????? ??????.doc) -- D:\Dropbox\My Documents\התחייבות שמירת סודיות.doc
[2013/11/02 16:08:53 | 000,026,041 | ---- | C] ()(D:\Dropbox\My Documents\??????? ?? ??????? - ????.pdf) -- D:\Dropbox\My Documents\התכתבות עם רייהלנד - סבתא.pdf
[2013/11/02 16:08:52 | 003,440,772 | ---- | C] ()(D:\Dropbox\My Documents\????? ???? ?? ???.pdf) -- D:\Dropbox\My Documents\האריה שאהב רק תות.pdf
[2013/11/02 16:08:52 | 000,588,180 | ---- | C] ()(D:\Dropbox\My Documents\???? ??????? ????? 7 25 10 12.pdf) -- D:\Dropbox\My Documents\הצעת התקשרות יוחנן 7 25 10 12.pdf
[2013/11/02 16:08:52 | 000,445,952 | ---- | C] ()(D:\Dropbox\My Documents\?? ???? ??????.doc) -- D:\Dropbox\My Documents\דף שעות לתגבור.doc
[2013/11/02 16:08:52 | 000,210,323 | ---- | C] ()(D:\Dropbox\My Documents\????? ????? ?? ?????? 2009.jpg) -- D:\Dropbox\My Documents\העברת בעלות על הדייהו 2009.jpg
[2013/11/02 16:08:52 | 000,102,400 | ---- | C] ()(D:\Dropbox\My Documents\?? ????? ????? ??????? ????.doc) -- D:\Dropbox\My Documents\דף ריכוז רנטות לניצולי שואה.doc
[2013/11/02 16:08:52 | 000,083,968 | ---- | C] ()(D:\Dropbox\My Documents\???? ?????? ???? ????? - 3.doc) -- D:\Dropbox\My Documents\הסכם שכירות בלתי מוגנת - 3.doc
[2013/11/02 16:08:52 | 000,033,280 | ---- | C] ()(D:\Dropbox\My Documents\??? ??? ??''?.doc) -- D:\Dropbox\My Documents\בתי ספר בת''א.doc
[2013/11/02 16:08:52 | 000,029,696 | ---- | C] ()(D:\Dropbox\My Documents\????? ????? ???????.doc) -- D:\Dropbox\My Documents\העברת תרומה לטנזניה.doc
[2013/11/02 16:08:52 | 000,025,600 | ---- | C] ()(D:\Dropbox\My Documents\???? ????? ??????? ????? ????????? ???????.doc) -- D:\Dropbox\My Documents\הכנה להגשת מועמדות לקורס דיפלומטיה ציבורית.doc
[2013/11/02 16:08:52 | 000,014,946 | ---- | C] ()(D:\Dropbox\My Documents\???? ????? - ??? ????? 85.docx) -- D:\Dropbox\My Documents\ברכה לסבתא - יום הולדת 85.docx
[2013/11/02 16:08:52 | 000,014,848 | ---- | C] ()(D:\Dropbox\My Documents\???? ???????? 29.xls) -- D:\Dropbox\My Documents\דירה בהסתדרות 29.xls
[2013/11/02 16:08:52 | 000,013,824 | ---- | C] ()(D:\Dropbox\My Documents\?????? ??? ?? ????.xls) -- D:\Dropbox\My Documents\הוצאות דלק של אביב.xls
[2013/11/02 16:08:51 | 006,259,200 | ---- | C] ()(D:\Dropbox\My Documents\???? ???? ??? ???? ?????? ??????.doc) -- D:\Dropbox\My Documents\ברכה לסבא צבי ליום הולדתו התשעים.doc
[2013/11/02 16:08:51 | 000,026,624 | ---- | C] ()(D:\Dropbox\My Documents\???? ???? ??? ???? ?????? ??????.ppt) -- D:\Dropbox\My Documents\ברכה לסבא צבי ליום הולדתו התשעים.ppt
[2013/11/02 16:08:50 | 000,348,792 | ---- | C] ()(D:\Dropbox\My Documents\????? ??? ???? ?????? ??? ????? ??? 37.jpg) -- D:\Dropbox\My Documents\בחירת עוד בקשר לתביעה נגד דיירי רמז 37.jpg
[2013/11/02 16:08:50 | 000,146,490 | ---- | C] ()(D:\Dropbox\My Documents\????? - ????? ???? ?????? ?.pdf) -- D:\Dropbox\My Documents\איילת - מערכת שעות סימסטר ב.pdf
[2013/11/02 16:08:50 | 000,103,936 | ---- | C] ()(D:\Dropbox\My Documents\???? ????.doc) -- D:\Dropbox\My Documents\ברכה ימית.doc
[2013/11/02 16:08:50 | 000,069,632 | ---- | C] ()(D:\Dropbox\My Documents\???? ??????.ppt) -- D:\Dropbox\My Documents\ברכה לחתונה.ppt
[2013/11/02 16:08:50 | 000,029,184 | ---- | C] ()(D:\Dropbox\My Documents\???? ??? ????? ?? ??? ????.doc) -- D:\Dropbox\My Documents\ברכה לבת מצווה של שלי שלגי.doc
[2013/11/02 16:08:50 | 000,000,165 | -H-- | C] ()(D:\Dropbox\My Documents\~$???? ????? ????.xlsx) -- D:\Dropbox\My Documents\~$שעות עבודה תאסק.xlsx
[2013/11/02 16:08:50 | 000,000,162 | -H-- | C] ()(D:\Dropbox\My Documents\~$?? ?-GMAT.doc) -- D:\Dropbox\My Documents\~$לה ב-GMAT.doc
[2013/11/02 16:08:37 | 072,934,378 | ---- | C] ()(D:\Dropbox\My Documents\2005__????_???_-_?????%2c_?????_???????_-_(?????.pdf) -- D:\Dropbox\My Documents\2005__יצחק_מור_-_לשרוד%2c_לשאוף_ולהגשים_-_(מוקטן.pdf
[2013/11/02 15:15:41 | 000,224,628 | ---- | M] ()(D:\Dropbox\My Documents\?? ????? ?? ???? ????.jpg) -- D:\Dropbox\My Documents\צק מבוטל של סבתא וסבא.jpg
[2013/11/01 16:59:13 | 000,017,535 | ---- | C] ()(C:\Documents and Settings\Aviv Shalgi\Desktop\????? ????????.xlsx) -- C:\Documents and Settings\Aviv Shalgi\Desktop\חברות מעניינות.xlsx
[2013/10/20 19:51:59 | 000,000,165 | -H-- | M] ()(D:\Dropbox\My Documents\~$???? ????? ????.xlsx) -- D:\Dropbox\My Documents\~$שעות עבודה תאסק.xlsx
[2013/10/16 17:22:50 | 000,011,824 | ---- | M] ()(D:\Dropbox\My Documents\???????? ?????.xlsx) -- D:\Dropbox\My Documents\פרויקטים בתאסק.xlsx
[2013/10/05 23:56:02 | 000,015,053 | ---- | M] ()(D:\Dropbox\My Documents\???? ???????? ???? ???? ???????.docx) -- D:\Dropbox\My Documents\מכתב למזכירות ועדת הערר לארנונה.docx
[2013/09/28 14:10:17 | 000,416,841 | ---- | M] ()(D:\Dropbox\My Documents\????? ????? - ????? ????? ??????.jpg) -- D:\Dropbox\My Documents\סריקה לסבתא - ארגון נפגעי הנאצים.jpg
[2013/09/28 14:10:14 | 000,517,688 | ---- | M] ()(D:\Dropbox\My Documents\????? ????? - ????? ????? ?????? 2.jpg) -- D:\Dropbox\My Documents\סריקה לסבתא - ארגון נפגעי הנאצים 2.jpg
[2013/09/27 19:21:55 | 000,000,000 | ---D | C](C:\Documents and Settings\Aviv Shalgi\Desktop\?????) -- C:\Documents and Settings\Aviv Shalgi\Desktop\איילת
[2013/08/22 16:36:49 | 000,281,563 | ---- | M] ()(C:\Documents and Settings\Aviv Shalgi\Desktop\?? ?????????? ??????.pdf) -- C:\Documents and Settings\Aviv Shalgi\Desktop\גם בלונדיניות יכולות.pdf
[2013/08/22 16:36:48 | 000,281,563 | ---- | C] ()(C:\Documents and Settings\Aviv Shalgi\Desktop\?? ?????????? ??????.pdf) -- C:\Documents and Settings\Aviv Shalgi\Desktop\גם בלונדיניות יכולות.pdf
[2013/08/03 19:35:52 | 000,013,575 | ---- | M] ()(D:\Dropbox\My Documents\???? - ???? ?????.docx) -- D:\Dropbox\My Documents\מעקה - דניה סיבוס.docx
[2013/07/03 21:01:15 | 000,016,138 | ---- | M] ()(D:\Dropbox\My Documents\???? 1.docx) -- D:\Dropbox\My Documents\מטלה 1.docx
[2013/06/21 14:53:01 | 000,080,391 | ---- | M] ()(D:\Dropbox\My Documents\???? ??????? - ?????? ?????? ????? - ????? ?? ????? ?????.pdf) -- D:\Dropbox\My Documents\משרד התחבורה - תשלומי רישיון נהיגה - הודעה על ביצוע תשלום.pdf
[2013/06/08 22:15:36 | 000,013,754 | ---- | M] ()(D:\Dropbox\My Documents\???? ??????? ?? ???? ???? ???? ?????? ??????.docx) -- D:\Dropbox\My Documents\מכתב לעיריית תל אביב בגין חיוב ארנונה ואגרות.docx
[2013/05/25 14:17:36 | 072,934,378 | ---- | M] ()(D:\Dropbox\My Documents\2005__????_???_-_?????%2c_?????_???????_-_(?????.pdf) -- D:\Dropbox\My Documents\2005__יצחק_מור_-_לשרוד%2c_לשאוף_ולהגשים_-_(מוקטן.pdf
[2013/04/27 12:00:28 | 000,001,036 | ---- | M] ()(D:\Dropbox\My Documents\????? ?????? ?? ????.xls.lnk) -- D:\Dropbox\My Documents\מתנות לחתונה של רעות.xls.lnk
[2013/03/08 16:07:07 | 000,020,042 | ---- | M] ()(C:\Documents and Settings\Aviv Shalgi\Desktop\????? ???? ?????? ??? ??????.jpg) -- C:\Documents and Settings\Aviv Shalgi\Desktop\ארנון איקה צילומי נשך לבדיקה.jpg
[2013/03/08 16:07:07 | 000,020,042 | ---- | C] ()(C:\Documents and Settings\Aviv Shalgi\Desktop\????? ???? ?????? ??? ??????.jpg) -- C:\Documents and Settings\Aviv Shalgi\Desktop\ארנון איקה צילומי נשך לבדיקה.jpg
[2013/03/01 21:34:10 | 000,312,051 | ---- | M] ()(C:\Documents and Settings\Aviv Shalgi\Desktop\????? ??? 5-12.JPG) -- C:\Documents and Settings\Aviv Shalgi\Desktop\הייטק זון 5-12.JPG
[2013/03/01 21:34:10 | 000,312,051 | ---- | C] ()(C:\Documents and Settings\Aviv Shalgi\Desktop\????? ??? 5-12.JPG) -- C:\Documents and Settings\Aviv Shalgi\Desktop\הייטק זון 5-12.JPG
[2013/03/01 21:03:12 | 000,500,841 | ---- | M] ()(C:\Documents and Settings\Aviv Shalgi\Desktop\???? ?????? ????? 2012.pdf) -- C:\Documents and Settings\Aviv Shalgi\Desktop\חוזה לפתיחת חשבון 2012.pdf
[2013/03/01 21:03:11 | 000,500,841 | ---- | C] ()(C:\Documents and Settings\Aviv Shalgi\Desktop\???? ?????? ????? 2012.pdf) -- C:\Documents and Settings\Aviv Shalgi\Desktop\חוזה לפתיחת חשבון 2012.pdf
[2013/03/01 16:20:30 | 000,014,946 | ---- | M] ()(D:\Dropbox\My Documents\???? ????? - ??? ????? 85.docx) -- D:\Dropbox\My Documents\ברכה לסבתא - יום הולדת 85.docx
[2013/02/18 21:06:58 | 000,146,490 | ---- | M] ()(D:\Dropbox\My Documents\????? - ????? ???? ?????? ?.pdf) -- D:\Dropbox\My Documents\איילת - מערכת שעות סימסטר ב.pdf
[2013/02/16 14:55:05 | 000,626,999 | ---- | M] ()(D:\Dropbox\My Documents\????? ???? ?? ??? 2.jpg) -- D:\Dropbox\My Documents\כרטיס עובד של סבא 2.jpg
[2013/02/16 14:53:59 | 000,473,235 | ---- | M] ()(D:\Dropbox\My Documents\????? ???? ?? ??? 1.jpg) -- D:\Dropbox\My Documents\כרטיס עובד של סבא 1.jpg
[2013/02/09 23:29:19 | 003,440,772 | ---- | M] ()(D:\Dropbox\My Documents\????? ???? ?? ???.pdf) -- D:\Dropbox\My Documents\האריה שאהב רק תות.pdf
[2013/01/20 21:01:40 | 000,612,613 | ---- | M] ()(D:\Dropbox\My Documents\????? ???????.pdf) -- D:\Dropbox\My Documents\תביעת מילואים.pdf
[2013/01/07 22:55:44 | 000,021,415 | ---- | M] ()(D:\Dropbox\My Documents\??? ???? - ????? ?????? 3.pdf) -- D:\Dropbox\My Documents\נסח טאבו - מורדי הגטאות 3.pdf
[2013/01/07 22:46:42 | 000,284,905 | ---- | M] ()(D:\Dropbox\My Documents\?? ???.jpg) -- D:\Dropbox\My Documents\תז אבא.jpg
[2012/12/29 20:16:48 | 000,013,556 | ---- | M] ()(C:\Documents and Settings\Aviv Shalgi\Desktop\?????? ????? 2013 - ???????.xlsx) -- C:\Documents and Settings\Aviv Shalgi\Desktop\המלצות השקעה 2013 - כלכליסט.xlsx
[2012/12/26 22:48:13 | 000,878,980 | ---- | M] ()(C:\Documents and Settings\Aviv Shalgi\Desktop\??? ???.docx) -- C:\Documents and Settings\Aviv Shalgi\Desktop\גיל פרץ.docx
[2012/12/26 22:27:20 | 000,618,856 | ---- | M] ()(C:\Documents and Settings\Aviv Shalgi\Desktop\Career Warfare - 10 ??????? ??????? ?????.pdf) -- C:\Documents and Settings\Aviv Shalgi\Desktop\Career Warfare - 10 הדיברות לקריירה מנצחת.pdf
[2012/12/26 22:27:20 | 000,618,856 | ---- | C] ()(C:\Documents and Settings\Aviv Shalgi\Desktop\Career Warfare - 10 ??????? ??????? ?????.pdf) -- C:\Documents and Settings\Aviv Shalgi\Desktop\Career Warfare - 10 הדיברות לקריירה מנצחת.pdf
[2012/12/26 20:55:31 | 000,878,980 | ---- | C] ()(C:\Documents and Settings\Aviv Shalgi\Desktop\??? ???.docx) -- C:\Documents and Settings\Aviv Shalgi\Desktop\גיל פרץ.docx
[2012/12/20 22:43:50 | 000,000,165 | -H-- | M] ()(C:\Documents and Settings\Aviv Shalgi\Desktop\~$?????? ????? 2013 - ???????.xlsx) -- C:\Documents and Settings\Aviv Shalgi\Desktop\~$המלצות השקעה 2013 - כלכליסט.xlsx
[2012/12/20 22:43:50 | 000,000,165 | -H-- | C] ()(C:\Documents and Settings\Aviv Shalgi\Desktop\~$?????? ????? 2013 - ???????.xlsx) -- C:\Documents and Settings\Aviv Shalgi\Desktop\~$המלצות השקעה 2013 - כלכליסט.xlsx
[2012/12/17 19:58:31 | 000,013,556 | ---- | C] ()(C:\Documents and Settings\Aviv Shalgi\Desktop\?????? ????? 2013 - ???????.xlsx) -- C:\Documents and Settings\Aviv Shalgi\Desktop\המלצות השקעה 2013 - כלכליסט.xlsx
[2012/11/11 22:14:09 | 001,242,232 | ---- | M] ()(C:\Documents and Settings\Aviv Shalgi\Desktop\???? ??? ??? ?????.jpg) -- C:\Documents and Settings\Aviv Shalgi\Desktop\נדלן לפי צבי סטפק‎.jpg
[2012/11/11 22:14:08 | 001,242,232 | ---- | C] ()(C:\Documents and Settings\Aviv Shalgi\Desktop\???? ??? ??? ?????.jpg) -- C:\Documents and Settings\Aviv Shalgi\Desktop\נדלן לפי צבי סטפק‎.jpg
[2012/11/10 19:43:35 | 000,009,791 | ---- | M] ()(C:\Documents and Settings\Aviv Shalgi\Desktop\???? ??? - ?????.jpg) -- C:\Documents and Settings\Aviv Shalgi\Desktop\קורן יעל - מבנים.jpg
[2012/11/10 19:22:14 | 000,009,791 | ---- | C] ()(C:\Documents and Settings\Aviv Shalgi\Desktop\???? ??? - ?????.jpg) -- C:\Documents and Settings\Aviv Shalgi\Desktop\קורן יעל - מבנים.jpg
[2012/10/29 21:43:57 | 000,588,180 | ---- | M] ()(D:\Dropbox\My Documents\???? ??????? ????? 7 25 10 12.pdf) -- D:\Dropbox\My Documents\הצעת התקשרות יוחנן 7 25 10 12.pdf
[2012/10/27 14:59:07 | 000,125,809 | ---- | M] ()(D:\Dropbox\My Documents\????? ??? ?? ???? ???? ???? ??? - ???.pdf) -- D:\Dropbox\My Documents\מיפוי עצם כל גופי כולל ספקט אגן - סבא.pdf
[2012/10/14 09:39:05 | 000,000,000 | ---D | M](C:\Documents and Settings\Aviv Shalgi\Desktop\??????) -- C:\Documents and Settings\Aviv Shalgi\Desktop\תמונות
[2012/10/13 15:25:44 | 000,000,000 | ---D | C](C:\Documents and Settings\Aviv Shalgi\Desktop\??????) -- C:\Documents and Settings\Aviv Shalgi\Desktop\תמונות
[2012/09/18 17:44:30 | 000,903,680 | ---- | M] ()(D:\Dropbox\My Documents\?????? ???? ???????.doc) -- D:\Dropbox\My Documents\מסמכים לקרן השתלמות.doc
[2012/09/15 13:43:58 | 000,146,007 | ---- | M] ()(D:\Dropbox\My Documents\????? ??????.jpg) -- D:\Dropbox\My Documents\סריקת דולרים.jpg
[2012/09/15 12:57:29 | 000,222,141 | ---- | M] ()(D:\Dropbox\My Documents\?? ?? ????.jpg) -- D:\Dropbox\My Documents\תז של סבתא.jpg
[2012/08/30 23:47:41 | 000,031,744 | ---- | M] ()(D:\Dropbox\My Documents\??????? - ????? ??????.xls) -- D:\Dropbox\My Documents\ערעורים - שאלון למועמד.xls
[2012/08/29 18:16:49 | 000,165,823 | ---- | M] ()(D:\Dropbox\My Documents\?? ???? ??? - ????.jpg) -- D:\Dropbox\My Documents\תז וספח מלא - אביב.jpg
[2012/08/26 17:38:23 | 000,011,011 | ---- | M] ()(C:\Documents and Settings\Aviv Shalgi\Desktop\??? ???? - ????.jpg) -- C:\Documents and Settings\Aviv Shalgi\Desktop\דני קורן - מבנה.jpg
[2012/08/26 17:38:23 | 000,011,011 | ---- | C] ()(C:\Documents and Settings\Aviv Shalgi\Desktop\??? ???? - ????.jpg) -- C:\Documents and Settings\Aviv Shalgi\Desktop\דני קורן - מבנה.jpg
[2012/07/18 21:31:34 | 000,327,739 | ---- | M] ()(D:\Dropbox\My Documents\???? ??????? 18.7.PDF) -- D:\Dropbox\My Documents\מכתב מפלאפון 18.7.PDF
[2012/07/11 22:33:05 | 000,000,000 | ---D | M](C:\Documents and Settings\Aviv Shalgi\Desktop\?????? ?????) -- C:\Documents and Settings\Aviv Shalgi\Desktop\תמונות לרעות
[2012/07/11 19:45:38 | 000,000,000 | ---D | C](C:\Documents and Settings\Aviv Shalgi\Desktop\?????? ?????) -- C:\Documents and Settings\Aviv Shalgi\Desktop\תמונות לרעות
[2012/06/09 14:54:51 | 000,029,696 | ---- | M] ()(D:\Dropbox\My Documents\????? ????? ???????.doc) -- D:\Dropbox\My Documents\העברת תרומה לטנזניה.doc
[2012/05/19 11:28:37 | 006,259,200 | ---- | M] ()(D:\Dropbox\My Documents\???? ???? ??? ???? ?????? ??????.doc) -- D:\Dropbox\My Documents\ברכה לסבא צבי ליום הולדתו התשעים.doc
[2012/05/19 10:59:39 | 000,000,000 | ---D | M](C:\Documents and Settings\Aviv Shalgi\Desktop\?????? ????) -- C:\Documents and Settings\Aviv Shalgi\Desktop\תמונות לסבא
[2012/05/19 10:53:28 | 000,026,624 | ---- | M] ()(D:\Dropbox\My Documents\???? ???? ??? ???? ?????? ??????.ppt) -- D:\Dropbox\My Documents\ברכה לסבא צבי ליום הולדתו התשעים.ppt
[2012/05/18 15:52:16 | 000,000,000 | ---D | C](C:\Documents and Settings\Aviv Shalgi\Desktop\?????? ????) -- C:\Documents and Settings\Aviv Shalgi\Desktop\תמונות לסבא
[2012/05/15 23:10:08 | 000,010,333 | ---- | M] ()(D:\Dropbox\My Documents\??? ????? ?????.xlsx) -- D:\Dropbox\My Documents\ימי הולדת לקלרה.xlsx
[2012/05/09 16:57:15 | 000,017,789 | ---- | M] ()(D:\Dropbox\My Documents\????? ??????? ???.xlsx) -- D:\Dropbox\My Documents\רשימת התקשרות ועד.xlsx
[2012/03/05 23:34:06 | 000,265,824 | ---- | M] ()(D:\Dropbox\My Documents\???? ?? ?????? ??????? - 1070088924.pdf) -- D:\Dropbox\My Documents\סירק דו סולייל כרטיסים - 1070088924.pdf
[2012/03/02 15:09:38 | 000,015,676 | ---- | M] ()(D:\Dropbox\My Documents\????? ?? ????.docx) -- D:\Dropbox\My Documents\פוקצה של רועי.docx
[2012/02/04 14:29:20 | 000,156,146 | ---- | M] ()(D:\Dropbox\My Documents\??? ??.jpg) -- D:\Dropbox\My Documents\סבא תז.jpg
[2012/01/17 21:19:31 | 000,612,004 | ---- | M] ()(D:\Dropbox\My Documents\?? ??????? 12.01.12.jpg) -- D:\Dropbox\My Documents\צו מילואים 12.01.12.jpg
[2011/12/24 20:22:53 | 000,028,160 | ---- | M] ()(D:\Dropbox\My Documents\????? ????????? ?????? ?????.xls) -- D:\Dropbox\My Documents\רשימה לסטודנטים למסיבת חנוכה.xls
[2011/12/15 20:06:19 | 000,061,841 | ---- | M] ()(D:\Dropbox\My Documents\?????? ?? ???.jpg) -- D:\Dropbox\My Documents\רישיון של אמא.jpg
[2011/12/14 19:02:29 | 000,104,376 | ---- | M] ()(D:\Dropbox\My Documents\?????????.jpg) -- D:\Dropbox\My Documents\סמארטקלאב.jpg
[2011/12/13 19:48:37 | 000,014,080 | ---- | M] ()(D:\Dropbox\My Documents\????? ????.docx) -- D:\Dropbox\My Documents\סמארט קלאב.docx
[2011/12/07 22:52:25 | 000,010,288 | ---- | M] ()(D:\Dropbox\My Documents\???? ???? ????? - ??.xlsx) -- D:\Dropbox\My Documents\מעקב גובה ומשקל - לי.xlsx
[2011/11/13 19:18:24 | 000,595,663 | ---- | M] ()(D:\Dropbox\My Documents\?????? ?????? ????? ???????????.docx) -- D:\Dropbox\My Documents\מסמכים לאישור חנייה באוניברסיטה.docx
[2011/11/13 19:10:35 | 000,322,038 | ---- | M] ()(D:\Dropbox\My Documents\?????? ??? - ???.jpg) -- D:\Dropbox\My Documents\רישיון רכב - קיה.jpg
[2011/11/13 19:07:15 | 000,060,217 | ---- | M] ()(D:\Dropbox\My Documents\?????? ????? - ????.jpg) -- D:\Dropbox\My Documents\רישיון נהיגה - אביב.jpg
[2011/11/12 18:36:30 | 000,084,016 | ---- | M] ()(D:\Dropbox\My Documents\????? ???? ?? ???? 2.jpg) -- D:\Dropbox\My Documents\תעודת זהות של סבתא 2.jpg
[2011/11/12 18:34:32 | 000,089,648 | ---- | M] ()(D:\Dropbox\My Documents\????? ???? ?? ????.jpg) -- D:\Dropbox\My Documents\תעודת זהות של סבתא.jpg
[2011/11/05 14:59:59 | 000,243,684 | ---- | M] ()(D:\Dropbox\My Documents\???? ?? ????? ?? ??? ?? ????.jpg) -- D:\Dropbox\My Documents\חוזה של החנות של אבא של סבתא.jpg
[2011/10/27 18:38:44 | 000,081,636 | ---- | M] ()(D:\Dropbox\My Documents\???? ????????? ??????.pdf) -- D:\Dropbox\My Documents\מנוי סמסטריאלי לחניון.pdf
[2011/10/14 18:02:19 | 000,000,000 | ---D | M](C:\Documents and Settings\Aviv Shalgi\Desktop\????? ?? ???) -- C:\Documents and Settings\Aviv Shalgi\Desktop\מצלמה של אבא
[2011/10/14 17:57:30 | 000,000,000 | ---D | C](C:\Documents and Settings\Aviv Shalgi\Desktop\????? ?? ???) -- C:\Documents and Settings\Aviv Shalgi\Desktop\מצלמה של אבא
[2011/10/11 12:27:16 | 000,023,040 | ---- | M] ()(D:\Dropbox\My Documents\???? ?-GMAT.doc) -- D:\Dropbox\My Documents\שאלה ב-GMAT.doc
[2011/10/11 12:27:16 | 000,000,162 | -H-- | M] ()(D:\Dropbox\My Documents\~$?? ?-GMAT.doc) -- D:\Dropbox\My Documents\~$לה ב-GMAT.doc
[2011/10/10 20:26:09 | 000,143,424 | ---- | M] ()(D:\Dropbox\My Documents\???? ?????????.pdf) -- D:\Dropbox\My Documents\שובר לקורדיליה.pdf
[2011/09/11 22:51:26 | 000,029,184 | ---- | M] ()(D:\Dropbox\My Documents\???? ??? ????? ?? ??? ????.doc) -- D:\Dropbox\My Documents\ברכה לבת מצווה של שלי שלגי.doc
[2011/08/24 20:58:07 | 000,116,503 | ---- | M] ()(D:\Dropbox\My Documents\????? ??? - ????.pdf) -- D:\Dropbox\My Documents\תשלום קנס - אביב.pdf
[2011/08/21 16:49:49 | 000,267,839 | ---- | M] ()(C:\Documents and Settings\Aviv Shalgi\Desktop\????? ?????.jpg) -- C:\Documents and Settings\Aviv Shalgi\Desktop\אישור ביטוח.jpg
[2011/08/21 16:49:47 | 000,267,839 | ---- | C] ()(C:\Documents and Settings\Aviv Shalgi\Desktop\????? ?????.jpg) -- C:\Documents and Settings\Aviv Shalgi\Desktop\אישור ביטוח.jpg
[2011/08/13 03:19:52 | 000,029,696 | ---- | M] ()(D:\Dropbox\My Documents\????? ???? - ???? ??? ?? ????? ????? ????? ???? - 12.08.doc) -- D:\Dropbox\My Documents\תמלול מקרה - קבלת דוח אי חגירת חגורה מאחור בנמל - 12.08.doc
[2011/07/05 19:58:02 | 000,037,888 | ---- | M] ()(D:\Dropbox\My Documents\???? ??????? ???? ???????? - ?????? ??????? ???.doc) -- D:\Dropbox\My Documents\מכתב לסוכנות החלל הישראלית - ספונסר להתמחות קיץ.doc
[2011/06/20 12:22:04 | 000,146,498 | ---- | M] ()(D:\Dropbox\My Documents\????? ???? ?????.jpg) -- D:\Dropbox\My Documents\משלוח ויזה לאלון.jpg
[2011/06/13 19:54:25 | 000,027,648 | ---- | M] ()(D:\Dropbox\My Documents\????? ??????? ???? ????? ?????.xls) -- D:\Dropbox\My Documents\רשימת מוזמנים ליום הולדת ביאיא.xls
[2011/06/13 19:53:51 | 000,193,536 | ---- | M] ()(D:\Dropbox\My Documents\????? ??????? ???? ????? ?????.doc) -- D:\Dropbox\My Documents\רשימת מוזמנים ליום הולדת ביאיא.doc
[2011/06/04 15:08:11 | 000,026,041 | ---- | M] ()(D:\Dropbox\My Documents\??????? ?? ??????? - ????.pdf) -- D:\Dropbox\My Documents\התכתבות עם רייהלנד - סבתא.pdf
[2011/06/04 14:55:38 | 000,348,792 | ---- | M] ()(D:\Dropbox\My Documents\????? ??? ???? ?????? ??? ????? ??? 37.jpg) -- D:\Dropbox\My Documents\בחירת עוד בקשר לתביעה נגד דיירי רמז 37.jpg
[2011/05/06 15:12:30 | 000,014,848 | ---- | M] ()(D:\Dropbox\My Documents\???? ???????? 29.xls) -- D:\Dropbox\My Documents\דירה בהסתדרות 29.xls
[2011/05/03 18:21:17 | 000,131,758 | ---- | M] ()(D:\Dropbox\My Documents\???? ?????? ?????.pdf) -- D:\Dropbox\My Documents\קבלה לנסיעה לאילת.pdf
[2011/03/03 21:59:58 | 000,343,720 | ---- | M] ()(D:\Dropbox\My Documents\?????? ????? ????.jpg) -- D:\Dropbox\My Documents\שירותי תיווך מענת.jpg
[2011/01/31 16:05:31 | 000,147,456 | ---- | M] ()(D:\Dropbox\My Documents\???? ?? ?????.ppt) -- D:\Dropbox\My Documents\קאזה דה ברזיל.ppt
[2011/01/02 18:53:01 | 000,154,792 | ---- | M] ()(D:\Dropbox\My Documents\??????? - ????? - ???? ?? ?????.pdf) -- D:\Dropbox\My Documents\חשבונית - גרופר - קאזה דה ברזיל.pdf
[2010/11/29 14:31:10 | 000,034,304 | ---- | M] ()(D:\Dropbox\My Documents\???? ???? ??? 38-???????.doc) -- D:\Dropbox\My Documents\הצעת מחיר תמא 38-גבעתיים.doc
[2010/09/30 15:35:47 | 005,595,695 | ---- | M] ()(D:\Dropbox\My Documents\???? ?????.pdf) -- D:\Dropbox\My Documents\קורס יזמות.pdf
[2010/08/20 20:16:49 | 000,065,558 | ---- | M] ()(D:\Dropbox\My Documents\????? ??????? ???? ????.pdf) -- D:\Dropbox\My Documents\כרטיס אוטובוס בניו יורק.pdf
[2010/08/09 22:00:01 | 000,040,960 | ---- | M] ()(D:\Dropbox\My Documents\???? ?????? - ??? ???.doc) -- D:\Dropbox\My Documents\חוזה למרפאה - שטר חוב.doc
[2010/08/09 21:58:14 | 000,104,960 | ---- | M] ()(D:\Dropbox\My Documents\???? ?????? - ????? - ????.doc) -- D:\Dropbox\My Documents\חוזה שכירות - מרפאה - סופי.doc
[2010/08/07 15:35:54 | 000,096,256 | ---- | M] ()(D:\Dropbox\My Documents\???? ?????? - ????? - ?????.doc) -- D:\Dropbox\My Documents\חוזה שכירות - מרפאה - טיוטא.doc
[2010/08/06 18:18:23 | 000,028,160 | ---- | M] ()(D:\Dropbox\My Documents\????? ????????? ?????? ??????? ??????.doc) -- D:\Dropbox\My Documents\מתכון לטורטליני גבינות עגבניות ומרווה.doc
[2010/07/02 23:02:08 | 000,035,328 | ---- | M] ()(D:\Dropbox\My Documents\??? 38 - ????.doc) -- D:\Dropbox\My Documents\תמא 38 - רעות.doc
[2010/06/29 21:31:27 | 000,024,576 | ---- | M] ()(D:\Dropbox\My Documents\????? ????? ?????.xls) -- D:\Dropbox\My Documents\חישוב מלגות לרעות.xls
[2010/06/29 17:53:27 | 000,024,576 | ---- | M] ()(D:\Dropbox\My Documents\???? ????? ????.xls) -- D:\Dropbox\My Documents\שעות עבודה בצבא.xls
[2010/06/27 19:41:46 | 000,000,000 | ---D | M](C:\Documents and Settings\Aviv Shalgi\Desktop\?????? ??????) -- C:\Documents and Settings\Aviv Shalgi\Desktop\תמונות להדפסה
[2010/06/27 19:20:47 | 000,000,000 | ---D | C](C:\Documents and Settings\Aviv Shalgi\Desktop\?????? ??????) -- C:\Documents and Settings\Aviv Shalgi\Desktop\תמונות להדפסה
[2010/06/12 12:49:57 | 000,155,343 | ---- | M] ()(D:\Dropbox\My Documents\???? ???? ????.jpg) -- D:\Dropbox\My Documents\מכתב לחנה שובל.jpg
[2010/06/04 17:50:44 | 000,029,184 | ---- | M] ()(D:\Dropbox\My Documents\???? ????? ?? ???? ????? 2010.doc) -- D:\Dropbox\My Documents\נספח לחוזה עם אמיר ויערה 2010.doc
[2010/06/01 18:53:25 | 000,014,848 | ---- | M] ()(D:\Dropbox\My Documents\???? ??????.xls) -- D:\Dropbox\My Documents\קובץ ממאורה.xls
[2010/05/31 17:36:28 | 000,445,952 | ---- | M] ()(D:\Dropbox\My Documents\?? ???? ??????.doc) -- D:\Dropbox\My Documents\דף שעות לתגבור.doc
[2010/05/19 21:54:27 | 000,673,570 | ---- | M] ()(D:\Dropbox\My Documents\????? ???? ????? ?1945 - 2.jpg) -- D:\Dropbox\My Documents\סריקת מסמך לסבתא מ1945 - 2.jpg
[2010/05/19 21:53:46 | 000,452,854 | ---- | M] ()(D:\Dropbox\My Documents\????? ???? ????? ?1945.jpg) -- D:\Dropbox\My Documents\סריקת מסמך לסבתא מ1945.jpg
[2010/05/19 21:52:44 | 000,163,179 | ---- | M] ()(D:\Dropbox\My Documents\???? ??'???? ?????.jpg) -- D:\Dropbox\My Documents\מכתב לג'נרלי מסבתא.jpg
[2010/05/19 13:18:20 | 000,024,576 | ---- | M] ()(D:\Dropbox\My Documents\????? ????? 19.05.10.doc) -- D:\Dropbox\My Documents\ערעור לסבתא 19.05.10.doc
[2010/03/24 20:02:15 | 000,025,890 | ---- | M] ()(C:\Documents and Settings\Aviv Shalgi\Desktop\??? ??? ?? ???.tif) -- C:\Documents and Settings\Aviv Shalgi\Desktop\כלל גמל של אמא.tif
[2010/03/24 20:02:06 | 000,025,890 | ---- | C] ()(C:\Documents and Settings\Aviv Shalgi\Desktop\??? ??? ?? ???.tif) -- C:\Documents and Settings\Aviv Shalgi\Desktop\כלל גמל של אמא.tif
[2010/01/16 19:41:29 | 000,000,000 | ---D | M](C:\Documents and Settings\Aviv Shalgi\Desktop\?????? ???????) -- C:\Documents and Settings\Aviv Shalgi\Desktop\תמונות מהמצלמה
[2010/01/07 17:46:27 | 000,103,936 | ---- | M] ()(D:\Dropbox\My Documents\???? ????.doc) -- D:\Dropbox\My Documents\ברכה ימית.doc
[2010/01/05 19:31:55 | 000,210,323 | ---- | M] ()(D:\Dropbox\My Documents\????? ????? ?? ?????? 2009.jpg) -- D:\Dropbox\My Documents\העברת בעלות על הדייהו 2009.jpg
[2010/01/05 19:31:35 | 000,122,681 | ---- | M] ()(D:\Dropbox\My Documents\????? ????? ????? 2009.jpg) -- D:\Dropbox\My Documents\תעודת ביטוח לאוטו 2009.jpg
[2010/01/03 22:08:24 | 000,030,208 | ---- | M] ()(D:\Dropbox\My Documents\???????? ????? ??????.doc) -- D:\Dropbox\My Documents\התחייבות שמירת סודיות.doc
[2009/12/28 21:34:44 | 000,012,800 | ---- | M] ()(D:\Dropbox\My Documents\????? ?? ?????.ppt) -- D:\Dropbox\My Documents\מכירה של האוטו.ppt
[2009/12/06 21:18:08 | 000,173,458 | ---- | M] ()(D:\Dropbox\My Documents\??? ????? ?????.jpg) -- D:\Dropbox\My Documents\שכר לימוד לאייל.jpg
[2009/11/06 14:39:55 | 000,025,600 | ---- | M] ()(D:\Dropbox\My Documents\???? ????? ??????? ????? ????????? ???????.doc) -- D:\Dropbox\My Documents\הכנה להגשת מועמדות לקורס דיפלומטיה ציבורית.doc
[2009/11/03 22:45:03 | 000,026,112 | ---- | M] ()(D:\Dropbox\My Documents\????? ?????? ?? ??? ????? ??? ?? ????? ?????.doc) -- D:\Dropbox\My Documents\תמלול השיחות עם יאן וחברה שלו על מכירת האוטו.doc
[2009/10/28 19:04:08 | 000,033,280 | ---- | M] ()(D:\Dropbox\My Documents\????? ????? ???? ????? ?????? ???.doc) -- D:\Dropbox\My Documents\זכרון דברים בדבר קניית ומכירת רכב.doc
[2009/09/29 16:42:52 | 000,105,177 | ---- | M] ()(D:\Dropbox\My Documents\?????? ???? ????? ??????? 30.09.09.html) -- D:\Dropbox\My Documents\כרטיסי טיסה ומלון לבודפשט 30.09.09.html
[2009/09/29 15:11:14 | 000,000,000 | ---D | C](C:\Documents and Settings\Aviv Shalgi\Desktop\?????? ???????) -- C:\Documents and Settings\Aviv Shalgi\Desktop\תמונות מהמצלמה
[2009/09/23 22:31:17 | 000,024,064 | ---- | M] ()(D:\Dropbox\My Documents\????? ?????.doc) -- D:\Dropbox\My Documents\מטמון חמיצר.doc
[2009/09/16 18:06:47 | 000,279,752 | ---- | M] ()(D:\Dropbox\My Documents\???? ?????? ????? ?? ??????? ??????? 2009.pdf) -- D:\Dropbox\My Documents\טופס לביטוח לאומי על מילואים בספטמבר 2009.pdf
[2009/08/23 19:49:15 | 000,343,040 | ---- | M] ()(D:\Dropbox\My Documents\???? ?????? ?? ???.ppt) -- D:\Dropbox\My Documents\קבלה ללפטופ של אבא.ppt
[2009/08/23 19:44:31 | 000,179,697 | ---- | M] ()(D:\Dropbox\My Documents\??????? ????? ???? 2.jpg) -- D:\Dropbox\My Documents\חשבונית אופיס דיפו 2.jpg
[2009/08/23 19:44:00 | 000,123,212 | ---- | M] ()(D:\Dropbox\My Documents\??????? ????? ????.jpg) -- D:\Dropbox\My Documents\חשבונית אופיס דיפו.jpg
[2009/07/31 10:17:32 | 000,083,968 | ---- | M] ()(D:\Dropbox\My Documents\???? ?????? ???? ????? - 3.doc) -- D:\Dropbox\My Documents\הסכם שכירות בלתי מוגנת - 3.doc
[2009/07/28 18:51:05 | 000,028,160 | ---- | M] ()(D:\Dropbox\My Documents\???? ????? ?? ????????? 2009.doc) -- D:\Dropbox\My Documents\נספח לחוזה עם גולדפינגר 2009.doc
[2009/05/16 18:16:16 | 000,094,208 | ---- | M] ()(D:\Dropbox\My Documents\??????? ???????.xls) -- D:\Dropbox\My Documents\חסכונות חודשיים.xls
[2009/04/29 11:40:08 | 000,033,280 | ---- | M] ()(D:\Dropbox\My Documents\??? ??? ??''?.doc) -- D:\Dropbox\My Documents\בתי ספר בת''א.doc
[2009/04/20 17:00:49 | 000,025,600 | ---- | M] ()(D:\Dropbox\My Documents\???? ????? ?????? - ????? ????? 2.doc) -- D:\Dropbox\My Documents\מכתב למשרד הרישוי - נהיגה מונעת 2.doc
[2009/04/12 18:25:57 | 000,145,516 | ---- | M] ()(D:\Dropbox\My Documents\??? ??????? ???? 2.jpg) -- D:\Dropbox\My Documents\קרן השתלמות רעות 2.jpg
[2009/04/12 14:39:44 | 000,013,824 | ---- | M] ()(D:\Dropbox\My Documents\?????? ??? ?? ????.xls) -- D:\Dropbox\My Documents\הוצאות דלק של אביב.xls
[2009/03/12 20:07:47 | 001,061,888 | ---- | M] ()(D:\Dropbox\My Documents\???? ???? ????? ??????? - ????? ???.doc) -- D:\Dropbox\My Documents\הצעת מחיר מעלית חיצונית - איציק לוי.doc
[2009/03/12 15:56:29 | 000,000,921 | ---- | M] ()(D:\Dropbox\My Documents\?????? ?????? ???.lnk) -- D:\Dropbox\My Documents\תיקיות השיתוף שלי.lnk
[2009/02/07 11:39:08 | 000,094,208 | ---- | C] ()(D:\Dropbox\My Documents\??????? ???????.xls) -- D:\Dropbox\My Documents\חסכונות חודשיים.xls
[2009/02/07 11:39:08 | 000,022,016 | ---- | C] ()(D:\Dropbox\My Documents\???? ????? ?????.doc) -- D:\Dropbox\My Documents\מכתב פרידה מחיים.doc
[2009/01/29 14:34:34 | 000,030,208 | ---- | M] ()(D:\Dropbox\My Documents\???? ???? ?????? ?? ????.doc) -- D:\Dropbox\My Documents\מייל לגבי הפנסיה של אביב.doc
[2008/12/27 21:37:56 | 000,022,016 | ---- | M] ()(D:\Dropbox\My Documents\???? ????? ?????.doc) -- D:\Dropbox\My Documents\מכתב פרידה מחיים.doc
[2008/12/08 22:21:57 | 000,029,696 | ---- | M] ()(D:\Dropbox\My Documents\??????? ??????.ppt) -- D:\Dropbox\My Documents\שיעורים פרטיים.ppt
[2008/12/07 10:31:22 | 001,086,976 | ---- | M] ()(D:\Dropbox\My Documents\?????? ???? ?????.ppt) -- D:\Dropbox\My Documents\סריקות לקרן פנסיה.ppt
[2008/11/27 21:45:23 | 000,024,064 | ---- | M] ()(D:\Dropbox\My Documents\?????.doc) -- D:\Dropbox\My Documents\להראל.doc
[2008/10/30 14:15:28 | 000,000,000 | ---D | M](C:\Documents and Settings\Aviv Shalgi\Desktop\?????) -- C:\Documents and Settings\Aviv Shalgi\Desktop\פסגות
[2008/10/30 14:14:44 | 000,000,000 | ---D | C](C:\Documents and Settings\Aviv Shalgi\Desktop\?????) -- C:\Documents and Settings\Aviv Shalgi\Desktop\פסגות
[2008/10/20 16:00:53 | 000,102,400 | ---- | M] ()(D:\Dropbox\My Documents\?? ????? ????? ??????? ????.doc) -- D:\Dropbox\My Documents\דף ריכוז רנטות לניצולי שואה.doc
[2008/10/09 16:59:04 | 000,824,832 | ---- | M] ()(D:\Dropbox\My Documents\??? ????? 60 ????.doc) -- D:\Dropbox\My Documents\יום הולדת 60 ליעל.doc
[2006/09/05 20:03:56 | 000,069,632 | ---- | M] ()(D:\Dropbox\My Documents\???? ??????.ppt) -- D:\Dropbox\My Documents\ברכה לחתונה.ppt
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 160 bytes -> D:\Dropbox\My Documents\Yael Moshkovitz - birth certificate.jpg:com.dropbox.attributes
@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0CE7F3C9
 
< End of report >
 
-------------------------------------------------------------------------------------------------
 

Extras.txt:

 

OTL Extras logfile created on: 18/01/2014 16:32:46 - Run 1
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Documents and Settings\Aviv Shalgi\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 0000040D | Country: Israel | Language: HEB | Date Format: dd/MM/yyyy
 
2.00 Gb Total Physical Memory | 0.36 Gb Available Physical Memory | 17.90% Memory free
3.85 Gb Paging File | 2.15 Gb Available in Paging File | 56.02% Paging File free
Paging file location(s): c:\pagefile.sys 2046 4092 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 48.83 Gb Total Space | 13.38 Gb Free Space | 27.40% Space Free | Partition Type: NTFS
Drive D: | 416.93 Gb Total Space | 72.42 Gb Free Space | 17.37% Space Free | Partition Type: NTFS
 
Computer Name: AVIV | User Name: Aviv Shalgi | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found
 
========== Shell Spawning ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Sync with Dropbox] -- "D:\Dropbox Folder Sync\Dropbox Folder Sync.exe" "%1" "sync" ()
Directory [UnSync with Dropbox] -- "D:\Dropbox Folder Sync\Dropbox Folder Sync.exe" "%1" "unsync" ()
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"UpdatesDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
"DisableMonitoring" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
 
========== System Restore Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"10950:TCP" = 10950:TCP:*:Enabled:skype
"5910:TCP" = 5910:TCP:*:Enabled:vnc5910
 
========== Authorized Applications List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)
"C:\Program Files\Winamp Remote\bin\Orb.exe" = C:\Program Files\Winamp Remote\bin\Orb.exe:*:Enabled:Orb -- (Orb Networks, Inc.)
"C:\Program Files\Winamp Remote\bin\OrbTray.exe" = C:\Program Files\Winamp Remote\bin\OrbTray.exe:*:Enabled:OrbTray -- (Orb Networks)
"C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe" = C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe:*:Enabled:Orb Stream Client -- (Orb Networks)
"C:\ICQ\ICQ6\ICQ.exe" = C:\ICQ\ICQ6\ICQ.exe:*:Enabled:ICQ6
"C:\Programs\BitTorrent\bittorrent.exe" = C:\Programs\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent -- (BitTorrent, Inc.)
"C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2009.SP2\RpcAgentSrv.exe" = C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2009.SP2\RpcAgentSrv.exe:*:Enabled:SiSoftware Deployment Agent Service -- (SiSoftware)
"C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2009.SP2\WNt500x86\RpcSandraSrv.exe" = C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2009.SP2\WNt500x86\RpcSandraSrv.exe:*:Enabled:SiSoftware Sandra Agent Service -- (SiSoftware)
"C:\Program Files\Microsoft LifeCam\LifeCam.exe" = C:\Program Files\Microsoft LifeCam\LifeCam.exe:*:Enabled:LifeCam.exe -- (Microsoft Corporation)
"C:\Program Files\Microsoft LifeCam\LifeExp.exe" = C:\Program Files\Microsoft LifeCam\LifeExp.exe:*:Enabled:LifeExp.exe -- (Microsoft Corporation)
"D:\uTorrent\uTorrent.exe" = D:\uTorrent\uTorrent.exe:*:Enabled:µTorrent -- (BitTorrent, Inc.)
"C:\ICQ\ICQ6.5\ICQ.exe" = C:\ICQ\ICQ6.5\ICQ.exe:*:Enabled:ICQ6 -- (ICQ, LLC.)
"C:\Program Files\Skype\Plugin Manager\skypePM.exe" = C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager
"C:\Program Files\Maple 12\jre\bin\maple.exe" = C:\Program Files\Maple 12\jre\bin\maple.exe:*:Disabled:Maple 12
"C:\Program Files\Google\Google Earth\client\googleearth.exe" = C:\Program Files\Google\Google Earth\client\googleearth.exe:*:Enabled:Google Earth -- (Google)
"C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe" = C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:*:Enabled:McAfee Network Agent
"C:\Documents and Settings\Aviv Shalgi\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe" = C:\Documents and Settings\Aviv Shalgi\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe:*:Enabled:Google Talk Plugin -- (Google)
"C:\Program Files\Bonjour\mDNSResponder.exe" = C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour Service -- (Apple Inc.)
"C:\Program Files\Microsoft Office\Office14\GROOVE.EXE" = C:\Program Files\Microsoft Office\Office14\GROOVE.EXE:*:Enabled:Microsoft SharePoint Workspace -- (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office14\ONENOTE.EXE" = C:\Program Files\Microsoft Office\Office14\ONENOTE.EXE:*:Enabled:Microsoft OneNote -- (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE" = C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook -- (Microsoft Corporation)
"C:\Documents and Settings\Aviv Shalgi\Application Data\Dropbox\bin\Dropbox.exe" = C:\Documents and Settings\Aviv Shalgi\Application Data\Dropbox\bin\Dropbox.exe:*:Enabled:Dropbox -- (Dropbox, Inc.)
"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent -- (BitTorrent, Inc.)
"C:\Program Files\Skype\Phone\Skype.exe" = C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype  -- (Skype Technologies S.A.)
"C:\Program Files\TeamViewer\Version7\TeamViewer.exe" = C:\Program Files\TeamViewer\Version7\TeamViewer.exe:*:Enabled:Teamviewer Remote Control Application -- (TeamViewer GmbH)
"C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe" = C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe:*:Enabled:Teamviewer Remote Control Service -- (TeamViewer GmbH)
"C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe" = C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe:*:Enabled:McAfee Shared Service Host -- (McAfee, Inc.)
"C:\Program Files\HP\HP Deskjet 2510 series\Bin\USBSetup.exe" = C:\Program Files\HP\HP Deskjet 2510 series\Bin\USBSetup.exe:LocalSubNet:Enabled:HP Device Setup (HP Deskjet 2510 series) -- (Hewlett-Packard Co.)
"C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe" = C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit -- (Apple Inc.)
"D:\iTunes\iTunes.exe" = D:\iTunes\iTunes.exe:*:Enabled:iTunes -- (Apple Inc.)
"C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe" = C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe:*:Enabled:McAfee Shared Service Host -- (McAfee, Inc.)
 
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{044F9133-B8D7-4d11-BF39-803FA20F5C8B}" = Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for Win32
"{0592EF96-69D8-4E4B-9CC9-88F58EA86F01}" = Apple Mobile Device Support
"{10CD364B-FFCC-48BE-B469-B9622A033075}" = Fences
"{13F3917B56CD4C25848BDC69916971BB}" = DivX Converter
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{18880887-285F-4260-989B-8B22020D756F}" = E-GOV.IL Sign&Verify Software - AGForm toolbar
"{1945A4B5-73B6-4DE9-99A3-05261B7FDED0}" = Shared C Run-time for x86
"{196E77C5-F524-4B50-BD1A-2C21EEE9B8F7}" = Microsoft SQL Server 2008 Common Files
"{1DA007FA-6A47-426B-8813-91A8BC75EC7D}" = HP Deskjet 2510 series Product Improvement Study
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = כלי ההעלאה של Windows Live
"{216C7F38-4BBC-4E9A-8392-C9FA21B54386}" = HP Deskjet 2510 series Setup Guide
"{234DADAD-3C3C-4FB1-90A4-0AF015D56E18}" = HP Deskjet 2510 series Help
"{26A24AE4-039D-4CA4-87B4-2F83217045FF}" = Java 7 Update 51
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{2A83AD05-56E6-3FBD-8752-B4143162EF59}" = Google Talk Plugin
"{2EEEC858-21F8-419B-8FE2-820621BFFCD7}" = GetDataBack for FAT
"{3108C217-BE83-42E4-AE9E-A56A2A92E549}" = Atheros Communications Inc.® AR8121/AR8113 Gigabit/Fast Ethernet Driver
"{342D4AD7-EC4C-4EC8-AEA6-E70F5905A490}" = SQL Server System CLR Types
"{37E0BDA5-DEAD-4116-8DC0-3F5C9A202C47}" = HP Deskjet 2510 series Basic Device Software
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3C3D696B-0DB7-3C6D-A356-3DB8CE541918}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{3E5CBADD-2E51-47C1-BBE2-B802DB6DA56A}" = USG Trader 4 Client Terminal 4.00
"{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker
"{455CF228-9805-4F94-9246-D475F4C90829}" = Citrix Online Launcher
"{46F044A5-CE8B-4196-984E-5BD6525E361D}" = Apple Application Support
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{4815BD99-96A4-49FE-A885-DCF06E9E4E78}" = Microsoft SQL Server 2008 Database Engine Shared
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A6F34E2-09E5-4616-B227-4A26A488A6F9}" = Microsoft SQL Server 2008 Common Files
"{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}" = Google Earth
"{56B83336-FBC1-4C46-8613-90A9E3B440D6}" = EPU-6 Engine
"{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}" = Microsoft Office Live Add-in 1.3
"{58721EC3-8D4E-4B79-BC51-1054E2DDCD10}" = Microsoft SQL Server 2008 Database Engine Services
"{5BE1E709-30E4-3D6D-A708-96CE8D5E5E8D}" = Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for .NET Framework - enu
"{60DE4033-9503-48D1-A483-7846BD217CA9}" = ICQ6.5
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{63AFACBC-4795-4A1B-8037-5085DC03FC54}" = Microsoft LifeCam
"{67A87D78-70B5-4999-85CA-DE4C26100C7A}" = IntelliCAD 2001
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6D8D64BE-F500-55B6-705D-DFD08AFE0624}" = Acrobat.com
"{6F1C00D2-25C2-4CBA-8126-AE9A6E2E9CD5}" = HP Update
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{7B63B2922B174135AFC0E1377DD81EC2}" = 
"{7c503e58-b2bc-11d5-978a-0050ba84f5f7}" = Neverwinter Nights
"{7CCEBC24-62DB-4280-A8EC-BFA49F167920}" = Software Update for Web Folders
"{842FAF7C-50EF-4463-9B8F-6222E1384D7D}" = Microsoft Windows SDK for Visual Studio 2008 Headers and Libraries
"{8795CBED-55E2-4693-9F14-84EC446935BE}" = SpeechRedist
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8AAB4176-A747-493A-A42C-B63CFADFD8E3}" = NVIDIA PhysX
"{8dae4336-2b71-11d4-9a6c-006067325e47}" = Baldur's Gate™ II - Shadows of Amn™
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-00A4-0409-0000-0000000FF1CE}" = Microsoft Office 2003 Web Components
"{90140000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders  (English) 14
"{90140000-0010-040D-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders  (Hebrew) 14
"{90140000-0015-040D-0000-0000000FF1CE}" = Microsoft Office Access MUI (Hebrew) 2010
"{90140000-0016-040D-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Hebrew) 2010
"{90140000-0018-040D-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Hebrew) 2010
"{90140000-0019-040D-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Hebrew) 2010
"{90140000-001A-040D-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Hebrew) 2010
"{90140000-001B-040D-0000-0000000FF1CE}" = Microsoft Office Word MUI (Hebrew) 2010
"{90140000-001F-0401-0000-0000000FF1CE}" = Microsoft Office Proof (Arabic) 2010
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-0000-0000000FF1CE}_Office14.VISIO_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-040C-0000-0000000FF1CE}_Office14.PROPLUSR_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040C-0000-0000000FF1CE}_Office14.VISIO_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040D-0000-0000000FF1CE}" = Microsoft Office Proof (Hebrew) 2010
"{90140000-001F-0419-0000-0000000FF1CE}" = Microsoft Office Proof (Russian) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}_Office14.VISIO_{DEA87BE2-FFCC-4F33-9946-FCBE55A1E998}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-002C-0409-0000-0000000FF1CE}_Office14.VISIO_{7CA93DF4-8902-449E-A42E-4C5923CFBDE3}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-040D-0000-0000000FF1CE}" = Microsoft Office Proofing (Hebrew) 2010
"{90140000-0044-040D-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Hebrew) 2010
"{90140000-0054-0409-0000-0000000FF1CE}" = Microsoft Office Visio MUI (English) 2010
"{90140000-0054-0409-0000-0000000FF1CE}_Office14.VISIO_{CDC4310F-8189-485F-B47D-D972217CE173}" = Microsoft Office 2010 Language Pack Service Pack 1 (SP1)
"{90140000-0057-0000-0000-0000000FF1CE}" = Microsoft Office Visio 2010
"{90140000-0057-0000-0000-0000000FF1CE}_Office14.VISIO_{01D8AE4B-A04D-47E5-81BF-E3F98B81B8C3}" = Microsoft Visio 2010 Service Pack 1 (SP1)
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-006E-0409-0000-0000000FF1CE}_Office14.VISIO_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-040D-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Hebrew) 2010
"{90140000-00A1-040D-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Hebrew) 2010
"{90140000-00BA-040D-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Hebrew) 2010
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}_Office14.VISIO_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{9028040D-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional עם FrontPage
"{91140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{91FD3E1D-FE00-4ECB-8379-204704812A9D}" = Crystal10
"{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195
"{9422C8EA-B0C6-4197-B8FC-DC797658CA00}" = Windows Live Sign-in Assistant
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9D6D76A6-4328-49E8-97A7-531A74841DA5}" = Microsoft SQL Server 2008 Setup Support Files (English)
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A8E9FAEE-4AC2-4A38-99D9-55D1F26F8163}" = TOEFL Sample Questions
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AAECF7BA-E83B-4A10-87EA-DE0B333F8734}" = RealNetworks - Microsoft Visual C++ 2010 Runtime
"{AC76BA86-1033-F400-7760-000000000003}" = Adobe Acrobat 8 Professional - English, Français, Deutsch
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.9)
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B5153233-9AEE-4CD4-9D2C-4FAAC870DBE2}" = Microsoft SQL Server 2008 Database Engine Services
"{B67BAFBA-4C9F-48FA-9496-933E3B255044}" = QuickTime
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{B857D868-F8B0-43EE-BC2B-D9E5ED21F237}" = Microsoft SQL Server VSS Writer
"{BFE903DE-4845-4387-9C6C-98B21B8445A3}" = GMATPrep™
"{C06CE867-0019-4BDD-88C3-CD96F79FCDC7}" = Cortona3D Viewer
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C3113E55-7BCB-4de3-8EBF-60E6CE6B2196}_is1" = SiSoftware Sandra Lite 2009.SP2
"{C688457E-03FD-4941-923B-A27F4D42A7DD}" = Microsoft SQL Server 2008 Browser
"{C8E8D2E3-EF6A-4B1D-A09E-7B27EBE2F3CE}" = RealDownloader
"{C965F01C-76EA-4BD7-973E-46236AE312D7}" = Sql Server Customer Experience Improvement Program
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CEEF7B2C-FE9A-492D-820B-EBCAB0927D3D}" = Release OrCAD 10.3
"{D3AE96EE-2876-4B3F-847C-D3A4AD689E43}" = LogMeIn
"{D481EA96-2313-4A7C-98EE-710D1AF884AC}" = Microsoft Visual Studio 2005 Tools for Applications - ENU
"{D8087907-E255-3A41-A46D-D0F798709C71}" = Microsoft Visual C++ 2008 Express Edition with SP1 - ENU
"{D9D937B0-E842-4130-9588-B948E876904A}" = Microsoft SQL Server 2008 Native Client
"{E05D82D8-FE70-4228-B073-B0C07FE27595}" = iTunes
"{E0B7CA7A-98B0-4EF1-87F5-FF6B02DC06A9}_is1" = Dropbox Folder Sync addon
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F1DC7648-8623-442F-92B7-E118DF61872E}" = Microsoft SQL Server 2008 RsFx Driver
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F3494AB6-6900-41C6-AF57-823626827ED8}" = Microsoft SQL Server 2008 Database Engine Shared
"{F4F8BF8F-4147-41AD-B3EB-9EB54F5CAB89}" = Audio Browser
"{F5E87B12-3C27-452F-8E78-21D42164FD83}" = Microsoft SQL Server 2008 Management Objects
"Adobe Acrobat 8 Professional - English, Français, Deutsch" = Adobe Acrobat 8.3.1 Professional
"Adobe Acrobat 8 Professional - English, Français, Deutsch_831" = Adobe Acrobat 8.3.1 - CPSID_83708
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"Amazon Kindle" = Amazon Kindle
"AoA Audio Extractor_is1" = AoA Audio Extractor 1.0
"Colmex Pro Trader Demo" = Colmex Pro Trader Demo
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"DAEMON Tools Lite" = DAEMON Tools Lite
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"DivX Setup" = DivX Setup
"DSMT5" = MathType 5
"Fences" = Fences
"Google Updater" = Google Updater
"GPL Ghostscript 8.63" = GPL Ghostscript 8.63
"Graph_is1" = Graph 4.3
"GSview 4.9" = GSview 4.9
"HP Photo Creations" = HP Photo Creations
"ie8" = Windows Internet Explorer 8
"Igor Pro" = Igor Pro
"Lexmark X5100 Series" = Lexmark X5100 Series
"Lizard Safeguard - PDF Viewer_is1" = Lizard Safeguard - PDF Viewer 2.6.19
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.75.0.1300
"Matlab R2012a" = MATLAB R2012a
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft SQL Server 10" = Microsoft SQL Server 2008
"Microsoft SQL Server 10 Release" = Microsoft SQL Server 2008
"Microsoft Visual C++ 2008 Express Edition with SP1 - ENU" = Microsoft Visual C++ 2008 Express Edition with SP1 - ENU
"Microsoft Visual Studio 2005 Tools for Applications - ENU" = Microsoft Visual Studio 2005 Tools for Applications - ENU
"MSC" = McAfee AntiVirus Plus
"mv61xxDriver" = marvell 61xx
"nero - burning rom!uninstallkey" = Nero 6 Demo
"NVIDIA Drivers" = NVIDIA Drivers
"Office14.PROPLUSR" = Microsoft Office Professional Plus 2010
"Office14.VISIO" = Microsoft Visio Premium 2010
"Orb" = Winamp Remote
"pokerstars.net" = PokerStars.net
"RealPlayer 16.0" = RealPlayer
"Recuva" = Recuva
"Revo Uninstaller" = Revo Uninstaller 1.83
"Small Citrix ICA Web Client" = MetaFrame Presentation Server Web Client (Minimal Installation)
"SystemRequirementsLab" = System Requirements Lab
"TeamViewer 7" = TeamViewer 7
"Total Video Converter 3.21_is1" = Total Video Converter 3.20 090114
"UT2004" = Unreal Tournament 2004
"uTorrent" = µTorrent
"Wdf01009" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
"WIC" = Windows Imaging Component
"Winamp" = Winamp
"WinDjView" = WinDjView 1.0.3
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"winscp3_is1" = WinSCP 4.1.7
"WMFDist11" = Windows Media Format 11 runtime
"Xvid_is1" = Xvid 1.1.3 final uninstall
 
========== HKEY_CURRENT_USER Uninstall List ==========
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"BitTorrent" = BitTorrent
"Dropbox" = Dropbox
"Google Chrome" = Google Chrome
"GoToMeeting" = GoToMeeting 5.7.0.1172
"UnityWebPlayer" = Unity Web Player
"utorrent" = µTorrent
"Warcraft III" = Warcraft III: All Products
"Winamp Detect" = Winamp Detector Plug-in
 
========== Last 20 Event Log Errors ==========
 
[ Application Events ]
Error - 16/01/2014 04:27:48 | Computer Name = AVIV | Source = AVG7 | ID = 100
Description = 2014-01-16 08:27:48,671 AVIV [000728:000732] ERROR 000 AVG7.AM HKEY_CLASSES_ROOT\AppId\{A434D6BB-090E-4DF6-8B03-AA04A6F58804}
 opening failed 
 
Error - 16/01/2014 17:51:04 | Computer Name = AVIV | Source = AVG7 | ID = 100
Description = 2014-01-16 21:51:04,984 AVIV [000792:000800] ERROR 000 AVG7.AM HKEY_CLASSES_ROOT\AppId\{A434D6BB-090E-4DF6-8B03-AA04A6F58804}
 opening failed 
 
Error - 17/01/2014 06:55:44 | Computer Name = AVIV | Source = AVG7 | ID = 100
Description = 2014-01-17 10:55:44,906 AVIV [000644:000648] ERROR 000 AVG7.AM HKEY_CLASSES_ROOT\AppId\{A434D6BB-090E-4DF6-8B03-AA04A6F58804}
 opening failed 
 
Error - 17/01/2014 15:01:40 | Computer Name = AVIV | Source = AVG7 | ID = 100
Description = 2014-01-17 19:01:40,718 AVIV [000760:000764] ERROR 000 AVG7.AM HKEY_CLASSES_ROOT\AppId\{A434D6BB-090E-4DF6-8B03-AA04A6F58804}
 opening failed 
 
Error - 17/01/2014 15:09:22 | Computer Name = AVIV | Source = AVG7 | ID = 100
Description = 2014-01-17 19:09:22,703 AVIV [000728:000732] ERROR 000 AVG7.AM HKEY_CLASSES_ROOT\AppId\{A434D6BB-090E-4DF6-8B03-AA04A6F58804}
 opening failed 
 
Error - 17/01/2014 19:09:39 | Computer Name = AVIV | Source = AVG7 | ID = 100
Description = 2014-01-17 23:09:39,968 AVIV [000932:000936] ERROR 000 AVG7.AM HKEY_CLASSES_ROOT\AppId\{A434D6BB-090E-4DF6-8B03-AA04A6F58804}
 opening failed 
 
Error - 18/01/2014 06:32:44 | Computer Name = AVIV | Source = AVG7 | ID = 100
Description = 2014-01-18 10:32:44,171 AVIV [000836:000840] ERROR 000 AVG7.AM HKEY_CLASSES_ROOT\AppId\{A434D6BB-090E-4DF6-8B03-AA04A6F58804}
 opening failed 
 
Error - 18/01/2014 06:37:53 | Computer Name = AVIV | Source = AVG7 | ID = 100
Description = 2014-01-18 10:37:53,328 AVIV [000768:000772] ERROR 000 AVG7.AM HKEY_CLASSES_ROOT\AppId\{A434D6BB-090E-4DF6-8B03-AA04A6F58804}
 opening failed 
 
Error - 18/01/2014 09:57:36 | Computer Name = AVIV | Source = AVG7 | ID = 100
Description = 2014-01-18 13:57:36,453 AVIV [000736:000740] ERROR 000 AVG7.AM HKEY_CLASSES_ROOT\AppId\{A434D6BB-090E-4DF6-8B03-AA04A6F58804}
 opening failed 
 
Error - 18/01/2014 10:10:07 | Computer Name = AVIV | Source = Application Error | ID = 1000
Description = Faulting application McSvHost.exe, version 3.8.703.0, faulting module
 unknown, version 0.0.0.0, fault address 0x006bf687.
 
[ System Events ]
Error - 18/01/2014 09:59:20 | Computer Name = AVIV | Source = DCOM | ID = 10005
Description = DCOM got error "%2" attempting to start the service wuauserv with 
arguments ""  in order to run the server:  {E60687F7-01A1-40AA-86AC-DB1CBF673334}
 
Error - 18/01/2014 09:59:20 | Computer Name = AVIV | Source = Service Control Manager | ID = 7000
Description = The Automatic Updates service failed to start due to the following
 error:   %%2
 
Error - 18/01/2014 09:59:22 | Computer Name = AVIV | Source = DCOM | ID = 10005
Description = DCOM got error "%2" attempting to start the service wuauserv with 
arguments ""  in order to run the server:  {E60687F7-01A1-40AA-86AC-DB1CBF673334}
 
Error - 18/01/2014 09:59:22 | Computer Name = AVIV | Source = Service Control Manager | ID = 7000
Description = The Automatic Updates service failed to start due to the following
 error:   %%2
 
Error - 18/01/2014 10:10:15 | Computer Name = AVIV | Source = Service Control Manager | ID = 7031
Description = The McAfee Home Network service terminated unexpectedly.  It has done
 this 1 time(s).  The following corrective action will be taken in 60000 milliseconds:
 Restart the service.
 
Error - 18/01/2014 10:10:15 | Computer Name = AVIV | Source = Service Control Manager | ID = 7031
Description = The McAfee Boot Delay Start Service service terminated unexpectedly.
  It has done this 1 time(s).  The following corrective action will be taken in 
60000 milliseconds: Restart the service.
 
Error - 18/01/2014 10:10:15 | Computer Name = AVIV | Source = Service Control Manager | ID = 7031
Description = The McAfee Personal Firewall Service service terminated unexpectedly.
  It has done this 1 time(s).  The following corrective action will be taken in 
60000 milliseconds: Restart the service.
 
Error - 18/01/2014 10:10:15 | Computer Name = AVIV | Source = Service Control Manager | ID = 7031
Description = The McAfee VirusScan Announcer service terminated unexpectedly.  It
 has done this 1 time(s).  The following corrective action will be taken in 60000
 milliseconds: Restart the service.
 
Error - 18/01/2014 10:10:15 | Computer Name = AVIV | Source = Service Control Manager | ID = 7031
Description = The McAfee Platform Services service terminated unexpectedly.  It 
has done this 1 time(s).  The following corrective action will be taken in 60000
 milliseconds: Restart the service.
 
Error - 18/01/2014 10:10:15 | Computer Name = AVIV | Source = Service Control Manager | ID = 7031
Description = The McAfee Proxy Service service terminated unexpectedly.  It has 
done this 1 time(s).  The following corrective action will be taken in 60000 milliseconds:
 Restart the service.
 
 
< End of report >
 

 


    Advertisements

Register to Remove


#2 oldman960

oldman960

    Forum God

  • Retired Classroom Teacher
  • 14,770 posts

Posted 18 January 2014 - 02:04 PM

Hi Shalgi, welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.
BitTorrent and µTorrent

You have BitTorrent and µTorrent, P2P/file sharing programs installed on your computer. P2P applications like it are the largest source of malware we see. You'll be doing yourself a favor by removing it.

References for the risk of these programs can be found in these links:
http://www.microsoft...protection.mspx

http://www.internetw...cles/art053.htm

I would recommend that you uninstall BitTorrent and µTorrent, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs.

If you wish to keep it, please do not use it until your computer is cleaned.

Please read through these instructions to familarize yourself with what to expect when this tool runs

Download ComboFix from:

Link 1

* IMPORTANT !!! Save ComboFix.exe to your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

RCUpdate1.png


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

RC2-1.png

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3.CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Proud Graduate of the WTT Classroon
If you are happy with the help you recieved, please consider making a Donation 5Iv60h9.jpg
Curiosity didn't kill the cat. Ignorance did, curiosity was framed.
Learn how to protect Yourself

Microsoft MVP 2011-2015

Threads will be closed if no response after 5 days.

#3 Shalgi

Shalgi

    New Member

  • Authentic Member
  • Pip
  • 17 posts

Posted 18 January 2014 - 03:49 PM

Hi Oldman960,

 

Thank you for the assistance.

Here is the CF log:

 

ComboFix 14-01-16.03 - Aviv Shalgi 01/18/2014  23:32:48.1.4 - x86
Microsoft Windows XP Professional  5.1.2600.3.1252.972.1033.18.2047.1065 [GMT 2:00]
Running from: c:\documents and settings\Aviv Shalgi\Desktop\ComboFix.exe
AV: AVG 7.5.432 *Disabled/Outdated* {41564737-3200-1071-989B-0000E87B4FB1}
AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Firewall *Disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
.
.
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\All Users\Application Data\xml120C.tmp
c:\documents and settings\All Users\Application Data\xml120E.tmp
c:\documents and settings\All Users\Application Data\xml1210.tmp
c:\documents and settings\Aviv Shalgi\g2mdlhlpx.exe
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\bebog._dl
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\jidijigytu.db
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\print.htm
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_addUserImage.ico
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_AgatUserImage.ico
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_Animated.htm
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_attachEmpty.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_attachFull.bmp
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_blue_bot_lft.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_bot_lft.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_bot_lft_dis.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_bot_rt.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_bot_rt_dis.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_btnSend.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_bullet.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_bullet_blue.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_bullet_blue_eng.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_but_asher.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_but_close.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_but_remove.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_but_sgor.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_corner_topLft.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_crnr_bot_left.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_crnr_bot_right.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_crnr_top_left.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_crnr_top_right.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_del_small.GIF
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_deleteSign.ico
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_displayAttach.ico
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_displaySignedForm.ico
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_displaySignerDetails.ico
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_displaySignerStatus.ico
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_dot.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_dotted_line.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_drop2.GIF
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_englishBackgroundPopup.jpg
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_englishContent.ico
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_exit.ico
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_form_bg_bottom_stretch.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_form_bg_corner_left.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_form_bg_corner_right.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_form_bg_left_stretch.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_form_bg_right_stretch.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_form1_main_bw.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_Header Misim.JPG
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_hebrewBackgroundPopup.jpg
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_hebrewContent.ico
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_ico_04_attachment.ico
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_id_card.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_ikon_files.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_ikon_help.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_ikon_tohen.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_layout_an_send_end.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_left_grey.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_left2.GIF
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_leftTop.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_line.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_line_dis.jpg
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_line_gray.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_line_stretch_across.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_line_stretch_down.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_lineee.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_logo_israel.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_logo_israel1.jpeg
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_lookUpWindow.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_lookUpWindowReadonly.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_main.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_main_left.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_main_semel.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_main_seperator.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_mashov.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_mysave.ico
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_New Header.jpg
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_print.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_print11.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_PrintFile.ico
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_printnush.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_question.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_questionMark.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_right_grey.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_right2.GIF
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_rightTop.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_sand_clock3.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_saveAllAttachments.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_saveAllAttachmentsENG.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_saveAttach.ico
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_SaveToFile.ico
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_saveToFileEach.ico
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_send.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_send11.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_send111.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_sendF.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_shadow_bottom.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_shadow_bottom_dis.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_shadow_Rt.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_shadow_Rt_dis.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_sign.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_sign_unverified.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_signGrey.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_signImg4.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_SignInQuestion.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_signYellow.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_square.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_star.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_status_Animated.htm
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_statusBar.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_subtitle_corner_left.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_subtitle_with_line.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_title_corner_left.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_title_corner_lft.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_title_with_line.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_titleBG.bmp
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_ToolbarP.png
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_top_lft.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_top_lft_dis.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_top_rt.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_top_rt_dis.gif
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_trash.ico
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsImg_verifySignature.ico
c:\documents and settings\Aviv Shalgi\Local Settings\Temporary Internet Files\tfsStatusBar.gif
c:\documents and settings\Aviv Shalgi\WINDOWS
C:\END
C:\LOG18E.tmp
c:\windows\c2.jpg
c:\windows\c3.jpg
c:\windows\c5.jpg
c:\windows\Downloaded Program Files\popcaploader.inf
c:\windows\EventSystem.log
c:\windows\jamutimaj._sy
c:\windows\system32\drivers\etc\hosts.ics
c:\windows\system32\winnt
c:\windows\system32\winnt\atl.dll
.
Infected copy of c:\windows\system32\kernel32.dll was found and disinfected 
Restored copy from - c:\windows\$hf_mig$\KB959426\SP3QFE\kernel32.dll 
.
.
(((((((((((((((((((((((((   Files Created from 2013-12-18 to 2014-01-18  )))))))))))))))))))))))))))))))
.
.
2014-01-17 12:51 . 2013-12-18 18:46 145408 ----a-w- c:\windows\system32\javacpl.cpl
2014-01-17 12:51 . 2013-12-18 19:10 94632 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-12-18 06:11 . 2013-12-18 06:11 354656 ----a-w- c:\windows\system32\DivXControlPanelApplet.cpl
2013-12-17 18:36 . 2011-07-20 17:37 86888 ----a-w- c:\windows\system32\LMIRfsClientNP.dll
2013-12-17 18:36 . 2011-07-20 17:37 53064 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\LMIproc.dll
2013-12-17 18:36 . 2011-07-20 17:37 31560 ----a-w- c:\windows\system32\LMIport.dll
2013-12-17 18:36 . 2011-07-20 17:37 85832 ----a-w- c:\windows\system32\LMIinit.dll
2013-12-12 21:46 . 2012-04-11 23:39 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-12-12 21:46 . 2011-06-05 16:52 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-12-12 21:46 . 2013-12-12 21:46 8699272 ----a-w- c:\windows\system32\FlashPlayerInstaller.exe
2013-11-26 20:06 . 2013-11-26 20:06 10152 ----a-w- c:\windows\system32\drivers\mfeclnrk.sys
2013-11-26 20:06 . 2013-11-26 20:06 80752 ----a-w- c:\windows\system32\drivers\mfencrk.sys
2013-11-26 20:06 . 2013-11-26 20:06 319808 ----a-w- c:\windows\system32\drivers\mfencbdc.sys
2013-11-04 15:22 . 2011-02-03 15:35 60920 ----a-w- c:\windows\system32\drivers\cfwids.sys
2013-11-04 15:16 . 2011-02-03 15:35 172416 ----a-w- c:\windows\system32\mfevtps.exe
2013-11-04 15:16 . 2011-02-03 15:35 91736 ----a-w- c:\windows\system32\drivers\mfetdi2k.sys
2013-11-04 15:12 . 2011-02-03 15:35 572528 ----a-w- c:\windows\system32\drivers\mfehidk.sys
2013-11-04 15:11 . 2011-02-03 15:35 85064 ----a-w- c:\windows\system32\drivers\mfendisk.sys
2013-11-04 15:10 . 2011-02-03 15:35 365416 ----a-w- c:\windows\system32\drivers\mfefirek.sys
2013-11-04 15:10 . 2011-02-03 15:35 65928 ----a-w- c:\windows\system32\drivers\mfebopk.sys
2013-11-04 15:09 . 2011-02-03 15:35 236000 ----a-w- c:\windows\system32\drivers\mfeavfk.sys
2013-11-04 15:08 . 2011-02-03 15:35 133992 ----a-w- c:\windows\system32\drivers\mfeapfk.sys
2013-10-26 17:22 . 2011-07-20 17:37 85832 ----a-w- c:\windows\system32\LMIinit.dll.000.bak
.
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown 
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-10 23:54 131248 ----a-w- c:\documents and settings\Aviv Shalgi\Application Data\Dropbox\bin\DropboxExt.22.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-10 23:54 131248 ----a-w- c:\documents and settings\Aviv Shalgi\Application Data\Dropbox\bin\DropboxExt.22.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-10 23:54 131248 ----a-w- c:\documents and settings\Aviv Shalgi\Application Data\Dropbox\bin\DropboxExt.22.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-10 23:54 131248 ----a-w- c:\documents and settings\Aviv Shalgi\Application Data\Dropbox\bin\DropboxExt.22.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OfficeSyncProcess"="c:\program files\Microsoft Office\Office14\MSOSYNC.EXE" [2010-12-20 718720]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Six Engine"="c:\program files\ASUS\Six Engine\SixEngine.exe" [2008-06-02 5964800]
"RTHDCPL"="RTHDCPL.EXE" [2008-05-16 16862720]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-03-27 13684736]
"nwiz"="nwiz.exe" [2009-03-27 1657376]
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2007-05-17 279912]
"VX1000"="c:\windows\vVX1000.exe" [2007-04-10 709992]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-03-27 86016]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2011-08-30 624056]
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2010-09-17 63048]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-09-13 59720]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
"DivXMediaServer"="c:\program files\DivX\DivX Media Server\DivXMediaServer.exe" [2013-12-23 450560]
"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2013-09-24 516912]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2011-10-28 49208]
"TkBellExe"="c:\program files\real\realplayer\update\realsched.exe" [2013-09-07 295512]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2013-05-01 421888]
"iTunesHelper"="d:\itunes\iTunesHelper.exe" [2013-10-01 152392]
"mcpltui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2013-09-24 516912]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2013-11-15 1861968]
.
c:\documents and settings\Aviv Shalgi\Start Menu\Programs\Startup\
Dropbox.lnk - c:\documents and settings\Aviv Shalgi\Application Data\Dropbox\bin\Dropbox.exe /systemstartup [2014-1-3 30714328]
Monitor Ink Alerts - HP Deskjet 2510 series.lnk - c:\windows\system32\RunDll32.exe "c:\program files\HP\HP Deskjet 2510 series\bin\HPStatusBL.dll",RunDLLEntry SERIALNUMBER=CN29Q3300N05TX;CONNECTION=USB;MONITOR=1; [2004-8-4 33280]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE -b -l [2001-2-12 83360]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{1984DD45-52CF-49cd-AB77-18F378FEA264}"= "c:\program files\Stardock\Fences\FencesMenu.dll" [2009-10-02 128360]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2013-12-17 18:36 85832 ----a-w- c:\windows\system32\LMIinit.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark X5100 Series]
2003-03-04 03:19 86100 ----a-w- c:\program files\Lexmark X5100 Series\lxbabmgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2013-05-01 01:59 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Winamp Remote\\bin\\Orb.exe"=
"c:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe"=
"c:\\Program Files\\Winamp Remote\\bin\\OrbStreamerClient.exe"=
"c:\\Programs\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\SiSoftware\\SiSoftware Sandra Lite 2009.SP2\\RpcAgentSrv.exe"=
"c:\\Program Files\\SiSoftware\\SiSoftware Sandra Lite 2009.SP2\\WNt500x86\\RpcSandraSrv.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"d:\\uTorrent\\uTorrent.exe"=
"c:\\ICQ\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Documents and Settings\\Aviv Shalgi\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Microsoft Office\\Office14\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office14\\ONENOTE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office14\\OUTLOOK.EXE"=
"c:\\Documents and Settings\\Aviv Shalgi\\Application Data\\Dropbox\\bin\\Dropbox.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\TeamViewer\\Version7\\TeamViewer.exe"=
"c:\\Program Files\\TeamViewer\\Version7\\TeamViewer_Service.exe"=
"c:\\Program Files\\Common Files\\McAfee\\McSvcHost\\McSvHost.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"d:\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Common Files\\McAfee\\Platform\\McSvcHost\\McSvHost.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"10950:TCP"= 10950:TCP:skype
"5910:TCP"= 5910:TCP:vnc5910
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
.
R?2 mcbootdelaystartsvc;McAfee Boot Delay Start Service;"c:\program files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe" /McCoreSvc [13/12/2013 13:05 281560]
R0 mv61xx;mv61xx;c:\windows\system32\drivers\mv61xx.sys [10/06/2008 12:33 150568]
R0 sptd;sptd;\SystemRoot\\SystemRoot\System32\Drivers\sptd.sys --> \SystemRoot\\SystemRoot\System32\Drivers\sptd.sys [?]
R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\system32\drivers\mfetdi2k.sys [03/02/2011 17:35 91736]
R2 HomeNetSvc;McAfee Home Network;"c:\program files\Common Files\Mcafee\Platform\McSvcHost\McSvHost.exe" /McCoreSvc [13/12/2013 13:05 281560]
R2 LMIGuardianSvc;LMIGuardianSvc;c:\program files\LogMeIn\x86\LMIGuardianSvc.exe [08/12/2010 12:11 375120]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [17/09/2010 14:40 13624]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [03/02/2011 12:25 104880]
R2 McAPExe;McAfee AP Service;c:\program files\McAfee\MSC\McAPExe.exe [13/12/2013 13:05 145088]
R2 McMPFSvc;McAfee Personal Firewall Service;"c:\program files\Common Files\Mcafee\Platform\McSvcHost\McSvHost.exe" /McCoreSvc [13/12/2013 13:05 281560]
R2 McNaiAnn;McAfee VirusScan Announcer;"c:\program files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe" /McCoreSvc [13/12/2013 13:05 281560]
R2 mcpltsvc;McAfee Platform Services;"c:\program files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe" /McCoreSvc [13/12/2013 13:05 281560]
R2 mfecore;McAfee Anti-Malware Core;c:\program files\Common Files\McAfee\AMCore\mcshield.exe [13/12/2013 13:06 643608]
R2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\mfefire.exe [03/02/2011 17:36 169320]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [03/02/2011 17:35 172416]
R2 RealNetworks Downloader Resolver Service;RealNetworks Downloader Resolver Service;c:\program files\RealNetworks\RealDownloader\rndlresolversvc.exe [14/08/2013 14:19 39056]
R2 Skype C2C Service;Skype C2C Service;c:\documents and settings\All Users\Application Data\Skype\Toolbars\Skype C2C Service\c2c_service.exe [22/11/2012 10:29 3290304]
R3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [03/02/2011 17:35 60920]
R3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [03/02/2011 17:35 365416]
R3 mfencbdc;McAfee Inc. mfencbdc;c:\windows\system32\drivers\mfencbdc.sys [26/11/2013 22:06 319808]
R3 mfendiskmp;mfendiskmp;c:\windows\system32\drivers\mfendisk.sys [03/02/2011 17:35 85064]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys --> c:\windows\system32\DRIVERS\Lbd.sys [?]
S1 bf629657;bf629657;c:\windows\system32\drivers\bf629657.sys --> c:\windows\system32\drivers\bf629657.sys [?]
S2 gupdate1c9863899e545c0;Google Update Service (gupdate1c9863899e545c0);c:\program files\Google\Update\GoogleUpdate.exe [03/02/2009 21:50 133104]
S2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [07/06/2012 18:12 160944]
S3 HipShieldK;McAfee Inc. HipShieldK;c:\windows\system32\drivers\HipShieldK.sys [22/12/2012 13:25 147912]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;\??\c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys --> c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys [?]
S3 mfencrk;McAfee Inc. mfencrk;c:\windows\system32\drivers\mfencrk.sys [26/11/2013 22:06 80752]
S3 mfendisk;McAfee Core NDIS Intermediate Filter;c:\windows\system32\drivers\mfendisk.sys [03/02/2011 17:35 85064]
S3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\drivers\netaapl.sys [21/08/2012 10:56 18432]
S3 SandraAgentSrv;SiSoftware Deployment Agent Service;c:\program files\SiSoftware\SiSoftware Sandra Lite 2009.SP2\RpcAgentSrv.exe [22/02/2009 16:52 98488]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\sqladhlp.exe [11/07/2008 02:28 47128]
S4 msvsmon80;Visual Studio 2005 Remote Debugger;c:\program files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [23/09/2005 06:01 2799808]
S4 RsFx0102;RsFx0102 Driver;c:\windows\system32\drivers\RsFx0102.sys [10/07/2008 02:49 242712]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [11/07/2008 02:28 369688]
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - WS2IFSL
.
Contents of the 'Scheduled Tasks' folder
.
2014-01-18 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-11 21:46]
.
2012-09-18 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 14:57]
.
2014-01-18 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-02-03 15:05]
.
2014-01-18 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-03 19:49]
.
2014-01-18 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-03 19:49]
.
2014-01-18 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-789336058-602609370-839522115-1003Core.job
- c:\documents and settings\Aviv Shalgi\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-07-02 13:42]
.
2014-01-18 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-789336058-602609370-839522115-1003UA.job
- c:\documents and settings\Aviv Shalgi\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-07-02 13:42]
.
2014-01-18 c:\windows\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-789336058-602609370-839522115-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2013-08-14 14:13]
.
2014-01-18 c:\windows\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-789336058-602609370-839522115-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2013-08-14 14:13]
.
2014-01-18 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-789336058-602609370-839522115-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2013-08-14 14:13]
.
2014-01-13 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-789336058-602609370-839522115-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2013-08-14 14:13]
.
2014-01-18 c:\windows\Tasks\User_Feed_Synchronization-{9ADC7FC0-9B82-41FE-8119-8BAC2B8B17DF}.job
- c:\windows\system32\msfeedssync.exe [2007-12-31 01:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://blekko.com/ws/?source=c3348dd4&toolbarid=blekkotb_031&u=E21E143E9DBD820563554A504B6D7539&tbp=homepage
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
IE: &????? ?? Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: &??? ?- Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: ?&?? ?? OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
Trusted Zone: cipcam.com\e3405
TCP: DhcpNameServer = 80.179.52.100 80.179.55.100
DPF: {A4150320-98EC-4DB6-9BFB-EBF4B6FBEB16} - hxxp://98.216.50.69:8000/codebase/DVM_IPCam2.ocx
.
- - - - ORPHANS REMOVED - - - -
.
HKCU-Run-Uniblue RegistryBooster 2009 - c:\program files\Uniblue\RegistryBooster\RegistryBooster.exe
HKU-Default-Run-AVG7_Run - c:\progra~1\Grisoft\AVGFRE~1\avgw.exe
MSConfigStartUp-MsnMsgr - c:\program files\Windows Live\Messenger\MsnMsgr.Exe
MSConfigStartUp-{0228e555-4f9c-4e35-a3ec-b109a192b4c2} - c:\program files\Google\Gmail Notifier\gnotify.exe
AddRemove-Igor Pro - c:\windows\unvise32.exe
AddRemove-{7B63B2922B174135AFC0E1377DD81EC2} - c:\program files\DivX\DivXCodecUninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2014-01-18 23:42
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...  
.
scanning hidden autostart entries ... 
.
scanning hidden files ...  
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_9_900_170_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_9_900_170_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(1060)
c:\windows\system32\LMIinit.dll
c:\windows\system32\LMIRfsClientNP.dll
.
- - - - - - - > 'explorer.exe'(5724)
c:\progra~1\mcafee\SITEAD~1\saHook.dll
c:\documents and settings\Aviv Shalgi\Application Data\Dropbox\bin\DropboxExt.22.dll
c:\progra~1\COMMON~1\MICROS~1\OFFICE14\Cultures\office.odf
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\OneX.DLL
c:\windows\system32\eappprxy.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Stardock\Fences\FencesMenu.dll
c:\program files\stardock\fences\DesktopDock.dll
c:\program files\WinSCP\DragExt.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\system32\LMIRfsClientNP.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre7\bin\jqs.exe
c:\program files\LogMeIn\x86\RaMaint.exe
c:\program files\Microsoft LifeCam\MSCamS32.exe
c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\program files\LogMeIn\x86\LogMeIn.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\RUNDLL32.EXE
c:\program files\Common Files\McAfee\Platform\mcuicnt.exe
c:\documents and settings\Aviv Shalgi\Application Data\Dropbox\bin\Dropbox.exe
c:\windows\system32\RunDll32.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\wscntfy.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
.
**************************************************************************
.
Completion time: 2014-01-18  23:48:29 - machine was rebooted
ComboFix-quarantined-files.txt  2014-01-18 21:48
.
Pre-Run: 14,157,410,304 bytes free
Post-Run: 14,963,204,096 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - 14B5221BC8EA64716C5E4614AD30E59A
8F558EB6672622401DA993E1E865C861


#4 oldman960

oldman960

    Forum God

  • Retired Classroom Teacher
  • 14,770 posts

Posted 19 January 2014 - 02:07 AM

Hi Shalgi,

How's the computer?

Let's see if that cleared things up. Run MBAM and see if the detections are gone now. Please post the MBAM log.

Proud Graduate of the WTT Classroon
If you are happy with the help you recieved, please consider making a Donation 5Iv60h9.jpg
Curiosity didn't kill the cat. Ignorance did, curiosity was framed.
Learn how to protect Yourself

Microsoft MVP 2011-2015

Threads will be closed if no response after 5 days.

#5 Shalgi

Shalgi

    New Member

  • Authentic Member
  • Pip
  • 17 posts

Posted 19 January 2014 - 11:23 AM

Wow, that was easier than I thought...

The Hijacks disappeared...

 

Thank you very much!

 

Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org
 
Database version: v2014.01.17.09
 
Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Aviv Shalgi :: AVIV [administrator]
 
19/01/2014 19:05:57
mbam-log-2014-01-19 (19-05-57).txt
 
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 280016
Time elapsed: 14 minute(s), 57 second(s)
 
Memory Processes Detected: 0
(No malicious items detected)
 
Memory Modules Detected: 0
(No malicious items detected)
 
Registry Keys Detected: 0
(No malicious items detected)
 
Registry Values Detected: 0
(No malicious items detected)
 
Registry Data Items Detected: 0
(No malicious items detected)
 
Folders Detected: 0
(No malicious items detected)
 
Files Detected: 0
(No malicious items detected)
 
(end)


#6 oldman960

oldman960

    Forum God

  • Retired Classroom Teacher
  • 14,770 posts

Posted 19 January 2014 - 12:34 PM

Hi Shalgi,

Looks good. We need to restore a file.

Open a new Notepad session
  • Click the Start button,
  • in the search box type notepad
  • click ok
  • In the notepad, Click "Format" and be certain that Word Wrap is not checked.
  • Copy and paste all the text in the code box below into the Notepad.
DeQuarantine::
C:\Qoobox\Quarantine\c\documents and settings\Aviv Shalgi\g2mdlhlpx.exe.vir

Quit::
In the notepad
  • Click File, Save as..., and set the Save in to your Desktop
  • In the filename box, type (including quotation marks) as the filename: "CFScript.txt"
  • Click save
Using your mouse left button, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown below.

This will start ComboFix again.Close all browser/windows first.

**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

CFScriptB-4.gif

A log called DeQuarantine.txt will be produced. Please post it's contents.



One more scan to check for stragglers.

As a Vista/Win7 user you will need to right click your browser icon and select "Run as Administrator" in order to run this scan.
  • Do not use this instance of your browser for anything besides doing this scan
  • When the scan is complete and the results saved, close that instance of your browser
  • Open a new one the usual way and post the results in this topic.
  • *Note
    It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
    Please don't go surfing while your resident protection is disabled!
    Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



    Go here to run an online scannner from
    ESET

    (Note: You can use Internet Explorer or FireFox for this scan. If you use FireFox you will be asked to install an additional component. Please allow this.)
    • Tick the box next to YES, I accept the Terms of Use.
    • Click Start
    • When asked, allow the activex control to install
    • Disable your Antivirus software. You can usually do this with its Notfication Tray icon near the clock
    • Click Start
    • Make sure that the option "Remove found threats" is Unchecked, and the option "Scan unwanted applications" is Checked.
    • Click Scan.
    • Wait for the scan to finish.
    • When the scan completes, click List of found threats
    • click Export to Text file and save the file to your desktop using a unique name, such as ESETScan.
    • Include the contents of this report in your next reply

      Note - when ESET doesn't find any threats, no report will be created.
    • Push the back button.
    • Push Finish
    • Re-enable your Antivirus software.
    Please post back with
    • Dequarantine log
    • ESET log

Proud Graduate of the WTT Classroon
If you are happy with the help you recieved, please consider making a Donation 5Iv60h9.jpg
Curiosity didn't kill the cat. Ignorance did, curiosity was framed.
Learn how to protect Yourself

Microsoft MVP 2011-2015

Threads will be closed if no response after 5 days.

#7 Shalgi

Shalgi

    New Member

  • Authentic Member
  • Pip
  • 17 posts

Posted 19 January 2014 - 01:10 PM

Hi oldman960,

 

I ran Combofix and here is the result:

 
C:\Qoobox\Quarantine\c\documents and settings\Aviv Shalgi\g2mdlhlpx.exe.vir -> c:\documents and settings\Aviv Shalgi\g2mdlhlpx.exe ( 60304 bytes ) 
 
Unfortunately I couldn't run ESET, it downloaded the initial database and got stuck at 96% saying "The proxy isn't configured properly", though I don't have any proxy (as far as I know) and I've disabled my firewall and my antivirus.
Any thoughts on how to bypass this problem?
 
Thank you again!
Shalgi


#8 oldman960

oldman960

    Forum God

  • Retired Classroom Teacher
  • 14,770 posts

Posted 19 January 2014 - 09:25 PM

Hi Shalgi,

Which browser did you use?

Proud Graduate of the WTT Classroon
If you are happy with the help you recieved, please consider making a Donation 5Iv60h9.jpg
Curiosity didn't kill the cat. Ignorance did, curiosity was framed.
Learn how to protect Yourself

Microsoft MVP 2011-2015

Threads will be closed if no response after 5 days.

#9 Shalgi

Shalgi

    New Member

  • Authentic Member
  • Pip
  • 17 posts

Posted 20 January 2014 - 03:54 AM

Usually chrome, but you wrote to use IE so mine is IE 8.

 

It might not be connected, but since we started our analysis my computer takes a longer time (2-3 minutes) to shutdown. When I press start->Turn off computer, it takes it about a minute or two for the window of "standby / restart / shutdown" to appear and then another couple of minutes after I press "shutdown" to actually shut down.

 

Any thoughts?


Edited by Shalgi, 20 January 2014 - 04:00 AM.


#10 oldman960

oldman960

    Forum God

  • Retired Classroom Teacher
  • 14,770 posts

Posted 21 January 2014 - 02:51 AM

Hi Shalgi,

I was sure I posted earlier but I don't see it.

Some people seem to have that problem with ESET, not sure why though. Try a different browser. It will work with Chrome or FireFox. You will be prompted to install Eset Smart Installer.

The slower shutdowns might be because we fixed a couple of services. They are both related to Windows Updates and will run in the back ground. According to the OTL log the last successful Auto Update was about 4 years ago. The BITS service is capable of "bookmarking" any downloads if it gets interupted so it doesn't need to start all over. It does take a bit of time for it to create it's file.

Proud Graduate of the WTT Classroon
If you are happy with the help you recieved, please consider making a Donation 5Iv60h9.jpg
Curiosity didn't kill the cat. Ignorance did, curiosity was framed.
Learn how to protect Yourself

Microsoft MVP 2011-2015

Threads will be closed if no response after 5 days.

    Advertisements

Register to Remove


#11 Shalgi

Shalgi

    New Member

  • Authentic Member
  • Pip
  • 17 posts

Posted 21 January 2014 - 07:50 AM

Hi,

 

I used chrome and downloaded as you've said.

Still the same problem, asking about a proxy.

 

:/

 

Should I run windows update or wait until we finish?



#12 oldman960

oldman960

    Forum God

  • Retired Classroom Teacher
  • 14,770 posts

Posted 22 January 2014 - 07:08 AM

Hi Shalgi,

If the updates have downloaded go ahead and install them. I'll try to find eiter a solution to ESET or another online scanner.

Proud Graduate of the WTT Classroon
If you are happy with the help you recieved, please consider making a Donation 5Iv60h9.jpg
Curiosity didn't kill the cat. Ignorance did, curiosity was framed.
Learn how to protect Yourself

Microsoft MVP 2011-2015

Threads will be closed if no response after 5 days.

#13 Shalgi

Shalgi

    New Member

  • Authentic Member
  • Pip
  • 17 posts

Posted 22 January 2014 - 04:19 PM

Hi,

 

I've finished installing all 215 updates, huh, that was long...

I'm not sure if it's connected, but the harddrive started making weird ticks.

 

I have no idea but ESET has started working again so I'm scanning my computer and will update with its log tomorrow.

 

Thanks for the help!



#14 oldman960

oldman960

    Forum God

  • Retired Classroom Teacher
  • 14,770 posts

Posted 22 January 2014 - 07:08 PM

Hi Shalgi,

Ok.

Proud Graduate of the WTT Classroon
If you are happy with the help you recieved, please consider making a Donation 5Iv60h9.jpg
Curiosity didn't kill the cat. Ignorance did, curiosity was framed.
Learn how to protect Yourself

Microsoft MVP 2011-2015

Threads will be closed if no response after 5 days.

#15 Shalgi

Shalgi

    New Member

  • Authentic Member
  • Pip
  • 17 posts

Posted 23 January 2014 - 03:19 AM

Well, I thought ESET was working but I was mistaken, still getting the proxy issue.

Any thoughts?


Related Topics



0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users